Bulletins

SIEMENS CERT
09/08/2026
Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.
SIEMENS CERT
09/08/2026
A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user’s session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim’s Teamcenter session. Siemens …
CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.

The following versions of IXON VPN Client are affected:

  • VPN Client <1.4.7 (CVE-2026-75925)
…
CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack …

CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.

The following versions of Rockwell Automation ControlFLASH are affected:

  • ControlFLASH <=V15.07 …
CISA (ALL)
09/03/2026

View CSAF

Summary

Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control …

CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.

The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected:

  • TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985)
  • …
CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.

The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected:

  • TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684)
…