Bulletins

CISA (ALL)
09/10/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition.

The following versions of NextGen Healthcare Mirth Connect are affected:

  • Mirth Connect <=v4.7.1 (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578)
CVSS Vendor
CISA (ALL)
09/10/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session.

The following versions of AVEVA Pipeline Integrity Monitor are affected:

  • AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513 (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824)
CISA (ALL)
09/10/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition.

The following versions …

CISA (ALL)
09/10/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.

The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected:

  • Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
CISA (ALL)
09/08/2026

Executive summary

China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI …

CISA (ALL)
09/08/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to take full control of the device.

The following versions of CareCam Pro IP Cameras are affected:

  • ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083)
CVSS Vendor Equipment
SIEMENS CERT
09/08/2026
A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of …
SIEMENS CERT
09/08/2026
WIBU Systems published information about a privilege escalation vulnerability under a certain circumstances and associated fix releases of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens industrial products. Siemens has released new versions for the affected products and recommends to update to the latest versions.