Bulletins

CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device.

The following versions of MZ Automation GmbH libiec61850 are affected:

  • libiec61850 <1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360)
CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic.

The following versions of MikroTik RouterOS are affected:

  • RouterOS …
CISA (ALL)
07/30/2026

CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat …

CISA (ALL)
07/30/2026

Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework …

CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition …

CISA (ALL)
07/30/2026

View CSAF

Summary

Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by …

BOSCH PSIRT
07/30/2026

BOSCH-SA-943700: Multiple vulnerabilities have been identified affecting the OpenSSH service configured within BSH ELP (Electronic Platform) modules. BSH Hausgeräte GmbH is a Bosch Group brand company. These modules are utilized across various connected home appliances (such as Bosch, Siemens, Gaggenau, and Neff). The vulnerabilities include a critical signal handler race …

CISA (ALL)
07/29/2026

CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM), that updates and replaces the minimum elements for an SBOM published by the National Telecommunications and Information Administration (NTIA) in 2021. The new …