Bulletins

CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device.

The following versions of Ebyte NA111-M are affected:

  • NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977)
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products.

The following versions of Mitsubishi Electric CNC Series (Update A) are affected:

  • Mitsubishi Electric M800VW (BND-2051W000) <=BB (CVE-2025-2399)
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.

The following versions of Xiiaozet LK100W are affected:

  • LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943)
CVSS Vendor Equipment Vulnerabilities
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.

The following versions of Rockwell Automation OTTO Fleet Manager are affected:

  • OTTO Fleet Manager <=V2.36.2 (CVE-2026-75112)
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product.

The following versions of Mitsubishi Electric Multiple FA Products (Update D) …

SIEMENS CERT
08/27/2026
The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script …
CISA (ALL)
08/26/2026

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  • CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability
  • CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
  • CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability
CISA (ALL)
08/26/2026

Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the …