Bulletins

CISA (ALL)
09/03/2026

CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing …

CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.

The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected:

  • TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985)
CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover.

The following versions of Rockwell Automation 1756-ENBT Module are affected:

  • 1756-ENBT module vers:all/* (CVE-2025-10478)
CVSS Vendor Equipment
CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.

The following versions of Rockwell Automation ControlFLASH are affected:

  • ControlFLASH <=V15.07 …
CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.

The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected:

  • UA-LDS-Installers <1.04.420 (CVE-2026-77477)
CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.

The following versions of IXON VPN Client are affected:

  • VPN Client <1.4.7 (CVE-2026-75925)
CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack …

SIEMENS CERT
09/03/2026
Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.