Bulletins

CISA (ALL)
08/06/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device.

The following versions of Johnson Controls Inc. TL280 are affected:

  • TL280 <5.63 
CVSS Vendor Equipment Vulnerabilities
CISA (ALL)
08/06/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data.

The following versions of ABB Ability Zenon are affected:

  • IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* 
CISA (ALL)
08/06/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened.

The following versions of Medixant RadiAnt DICOM are affected:

  • RadiAnt DICOM <=2025.2
CVSS
CISA (ALL)
08/04/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations.

The following versions of Acrisure KARR BT and DR-100 are affected:

  • KARR BT firmware <July_20_2026
  • DR-100 firmware <July_20_2026
CVSS
CISA (ALL)
08/04/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results.

The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected:

  • Applied Biosystems 3500/3500xL Series Data Collection …
CISA (ALL)
07/30/2026

View CSAF

Summary

Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by …

CISA (ALL)
07/30/2026

CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat …

CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.

The following versions of Johnson Controls OpenBlue Employee are affected:

  • OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497)