Bulletins

CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image.

The following versions of PayRange API are affected:

  • PayRange …
CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation.

The following versions of Ebyte NE2-D11 are affected:

  • NE2-D11 Firmware FW-9167-0-11
CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user.

The following versions of Zoneminder are affected:

  • Zoneminder 1.37.48|1.38.3 
CVSS Vendor Equipment Vulnerabilities
CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control.

The following versions of Bendix EC80 Brake ECU are affected:

  • EC80ESP+ J1708 Z228999
  • EC80ESP+ 6S/6M …
CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to alter device settings.

The following versions of FURUNO FA-50 Class B AIS Transponder are affected:

  • FURUNO FA-50 Class B AIS Transponder vers:all/*
CVSS Vendor
CISA (ALL)
08/20/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.

The following versions of Johnson Controls Simplex Incident Manager …

CISA (ALL)
08/19/2026

Executive summary

Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content …