Bulletins

CISA (ALL)
08/20/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.

The following versions of Johnson Controls Simplex Incident Manager …

CISA (ALL)
08/19/2026

Executive summary

Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content …

CISA (ALL)
08/18/2026

View CSAF

Summary

Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage …

CISA (ALL)
08/18/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code.

The following versions of CISA Malcolm are affected:

  • Malcolm <26.06.1 (CVE-2026-55676)
  • Malcolm <26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)
  • Malcolm <=26.07.1 (CVE-2026-19670, CVE-2026-19671)
CISA (ALL)
08/13/2026

View CSAF

Summary

Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and …

CISA (ALL)
08/13/2026

View CSAF

Summary

Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.

The …

CISA (ALL)
08/13/2026

View CSAF

Summary

A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the …

CISA (ALL)
08/13/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access.

The following versions …