Summary
Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access.
The following versions of MikroTik RouterOS and Cloud Hosted Router are affected:
- RouterOS vers:all/* (CVE-2026-16347)
- Cloud Hosted Router vers:all/* (CVE-2026-16347)
Summary
Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services.
The following versions of igloohome Smart Lock Mobile Application are affected:
- Smart Lock Mobile Application (Android) 3.2.3 (CVE-2026-16581)
| CVSS | … |
|---|
Summary
Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.
The following versions of Weintek cMT3092X are affected:
- cMT3092X firmware <20210218
- EasyWeb <v2.1.20
| CVSS | … |
|---|
Summary
Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.
The following versions of Johnson Controls XAAP Android are affected:
- XAAP Android <1.53
| CVSS | Vendor | Equipment | Vulnerabilities | …
|---|
Summary
Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service.
The following versions of MZ Automation lib60870 are affected:
- lib60870 <=2.4.0
| CVSS | Vendor | Equipment | … |
|---|
Summary
Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.
The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected:
- C-CURE 9000 and victor <=v2.90_v3.0
- victor Web <=v7.1
Summary
Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.
The following versions of MZ Automation libIEC61850 are affected:
- libIEC61850 >=v1.0.0|<=v1.6.1
Executive summary
A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian …