Bulletins

CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems.

The following versions of All-Line Equipment Company Fuel-Boss are affected:

  • Fuel-Boss V1 Standard >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
  • Fuel-Boss V1 Portal >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device.

The following versions of Ebyte NA111-M are affected:

  • NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977)
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products.

The following versions of Mitsubishi Electric CNC Series (Update A) are affected:

  • Mitsubishi Electric M800VW (BND-2051W000) <=BB (CVE-2025-2399)
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.

The following versions of Xiiaozet LK100W are affected:

  • LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943)
CVSS Vendor Equipment Vulnerabilities
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.

The following versions of Rockwell Automation OTTO Fleet Manager are affected:

  • OTTO Fleet Manager <=V2.36.2 (CVE-2026-75112)
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product.

The following versions of Mitsubishi Electric Multiple FA Products (Update D) …

SIEMENS CERT
08/27/2026
The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script …
CISA (ALL)
08/26/2026

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  • CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability
  • CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
  • CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability