Bulletins

CISA (ALL)
06/30/2026

View CSAF

Summary

Schneider Electric is aware of a vulnerability in its EcoStruxure™ IT Data Center Expert. The EcoStruxure™ IT Data Center Expert product is a scalable monitoring software that collects, organizes, and distributes critical device information providing a comprehensive view of equipment. Failure to apply the remediation …

CISA (ALL)
06/30/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow attackers to gain broad unauthorized access, execute arbitrary commands with root privileges, steal sensitive data, and perform actions on behalf of legitimate users across interconnected systems.

The following versions of StoneFly Storage Concentrator are affected:

CISA (ALL)
06/30/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow a local attacker to tamper with or destroy information in the affected product, cause a denial-of-service condition in the affected product, or execute arbitrary code when a specially crafted archive file is decompressed by the 7-Zip component included …

CISA (ALL)
06/30/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to write files, access unauthorized information, exhaust memory, or crash affected DCMTK client or server processes.

The following versions of OFFIS DCMTK Toolkit are affected:

  • DCMTK <=3.7.0 (CVE-2026-50003, CVE-2026-50254, CVE-2026-35505, CVE-2026-52868, CVE-2026-44628)
CISA (ALL)
06/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to enumerate all user accounts and role assignments on a FUXA SCADA/HMI instance.

The following versions of Frangoteam FUXA SCADA/HMI are affected:

  • FUXA SCADA/HMI <=1.3.1 (CVE-2026-13207)
CISA (ALL)
06/30/2026

View CSAF

Summary

An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or corrupt memory data.

The following versions of XZ Utils vulnerability impacting B&R Products …

SIEMENS CERT
06/30/2026
Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Siemens has released new versions for …
CISA (ALL)
06/29/2026

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.