Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2026-076
July 28, 2026, 12:00 PM
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, …
VDE-2026-081
July 28, 2026, 11:00 AM
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior …
VDE-2026-085
July 28, 2026, 11:00 AM
A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands.
VDE-2026-077
July 27, 2026, 12:00 PM
The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file …
VDE-2026-045
July 16, 2026, 12:00 PM
A vulnerability was discovered in several Endress+Hauser products that can be accessed via ethernet.
VDE-2026-063
July 14, 2026, 1:00 PM
Multiple Murrelektronik network-enabled devices respond to SNMPv2c 'GETBULK' requests with disproportionately large response packets when the requesting party specifies a large max-repetitions value. This response amplification allows the affected devices …
VDE-2026-062
July 14, 2026, 12:00 PM
Several Murrelektronik devices using Profinet are shipped with the default SNMP community names ('public' for read access and 'private' for write access). If these community strings remain unchanged in the …
VDE-2026-066
July 14, 2026, 12:00 PM
This update deploys cumulative Microsoft Windows security patches through March 2026 for LTSB 2016, LTSC 2019, and LTSC 2021.