Summary
Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.
The following versions of Johnson Controls Simplex Incident Manager …
Executive summary
Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content …
Summary
Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage …
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code.
The following versions of CISA Malcolm are affected:
- Malcolm <26.06.1 (CVE-2026-55676)
- Malcolm <26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)
- Malcolm <=26.07.1 (CVE-2026-19670, CVE-2026-19671)
Summary
Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization.
The following versions of AVEVA Enterprise SCADA are affected:
- Enterprise SCADA 2025 (CVE-2025-7639)
- Enterprise SCADA >=2024|<=2024_SP1_P01 (CVE-2025-7639)
- Enterprise SCADA …
Summary
Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about …
Summary
Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations.
The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected:
- HIPASE-250 <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313)
- 250 SCALA <=7.20 …