Bulletins

CISA (ALL)
07/21/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.

The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected:

  • TPDIN-Monitor-WEB2 2.3.9 
CISA (ALL)
07/21/2026

View CSAF

Summary

SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version.

The following versions of …

CISA (ALL)
07/21/2026

View CSAF

Summary

CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

CISA (ALL)
07/21/2026

View CSAF

Summary

Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.

The following versions of Siemens …

CISA (ALL)
07/21/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory.

The following versions of Rockwell Automation ThinManager are affected:

  • ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2
CISA (ALL)
07/21/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations.

The following versions of Rockwell Automation FactoryTalk Services Platform are affected:

  • FactoryTalk Directory (FTSP) 6.60 
BOSCH PSIRT
07/21/2026

BOSCH-SA-466086: The GitHub Security Lab has discovered a vulnerability in 7-Zip 26.00 and older: A heap buffer overflow vulnerability (GHSL-2026-140) exists in 7-Zip version 26.00, caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to exploit this issue for arbitrary code execution or …

CISA (ALL)
07/16/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.

The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are affected:

  • 1756-EN3 <=V12.001 (CVE-2026-9653)
  • 1756-EN2 <=V12.001 (CVE-2026-9653)
  • 1756-ENBT V6.006 (CVE-2026-9653)