Bulletins

CISA (ALL)
09/24/2026

View CSAF

Summary

This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.

The following versions of Siemens Mendix Runtime are affected:

  • Siemens Mendix Runtime vers:all/* (CVE-2026-7891)
CVSS …
CISA (ALL)
09/24/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation.

The following versions of Botslab G980H Dashcams are affected:

  • G980H dash cam series …
CISA (ALL)
09/24/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code.

The following versions of Eufy Omni C20, Omni X10 Pro are affected:

  • Omni C20 <1.6.4 (CVE-2026-93289, CVE-2026-93290, CVE-2026-93291)
  • Omni X10 Pro <1.6.4 (CVE-2026-93289)
  • …
CISA (ALL)
09/23/2026

Introduction

The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators.

ICS is …

CISA (ALL)
09/22/2026

View CSAF

Summary

Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not …

CISA (ALL)
09/22/2026

View CSAF

Summary

A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation …

CISA (ALL)
09/22/2026

View CSAF

Summary

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.

The following versions of Siemens SIMOVE …

CISA (ALL)
09/22/2026

View CSAF

Summary

Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system.

The following versions of lwIP (Lightweight IP) are affected:

  • API >=2.0.1|<=2.2.1 (CVE-2026-91018)
…