Bulletins

SIEMENS CERT
07/14/2026
Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks’ upstream security notifications. [1] https://security.paloaltonetworks.com/
SIEMENS CERT
07/14/2026
Simcenter STAR-CCM+ contains an information disclosure vulnerability when using the Power-on-Demand public license server. An attacker could access a system’s host, user, and display name. Siemens has updated the public Power-on-Demand public license server.
CISA (ALL)
07/13/2026

Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors

Executive summary

Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s

CISA (ALL)
07/09/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem and escalate this into arbitrary native code execution through the normal OpenPLC program compilation process, potentially resulting in code execution as the OpenPLC runtime user.

The following …

CISA (ALL)
07/09/2026

View CSAF

Summary

Schneider Electric is aware of a vulnerability in its Easergy MiCOM Px40 Series products. The [Easergy MiCOM Px40](https://www.se.com/ww/en/product-subcategory/4725-easergy-micom-px40-series/?filter=business-6-medium-voltage-distribution-and-grid-automation) is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. Failure to apply the mitigations provided below may risk unauthorized exposure of …

SIEMENS CERT
07/09/2026
Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: SICAM A8000 Device firmware CPCI85 for CP-8031/CP-8050 SICORE for CP-8010/CP-8012 SICAM EGS Device firmware CPCI85 SICAM S8000 SICORE Siemens has released new versions for the affected products and recommends to update to the …
CISA (ALL)
07/07/2026

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  • CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
  • CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability  
  • CVE-2026-56290 Joomlack Page Builder Improper …
CISA (ALL)
07/07/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations.

The following versions of Labcenter Proteus 9 are affected:

  • Proteus 9.1_SP4_Build_42914
CVSS Vendor Equipment