Bulletins

CISA (ALL)
08/25/2026

View CSAF

Summary

SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released …

CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to alter device settings.

The following versions of FURUNO FA-50 Class B AIS Transponder are affected:

  • FURUNO FA-50 Class B AIS Transponder vers:all/*
CVSS Vendor
CISA (ALL)
08/25/2026

Advisory at a Glance

Title A Tale of Two SOCs: Insights From Two Red Team Assessments
Original Publication  August 25, 2026
Executive Summary

The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at …

CISA (ALL)
08/20/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.

The following versions of Johnson Controls Simplex Incident Manager …

CISA (ALL)
08/19/2026

Executive summary

Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content …

CISA (ALL)
08/18/2026

View CSAF

Summary

Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage …

CISA (ALL)
08/18/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code.

The following versions of CISA Malcolm are affected:

  • Malcolm <26.06.1 (CVE-2026-55676)
  • Malcolm <26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)
  • Malcolm <=26.07.1 (CVE-2026-19670, CVE-2026-19671)