Bulletins

CISA (ALL)
08/26/2026

Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the …

CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to alter device settings.

The following versions of FURUNO FA-50 Class B AIS Transponder are affected:

  • FURUNO FA-50 Class B AIS Transponder vers:all/*
CVSS Vendor
CISA (ALL)
08/25/2026

Advisory at a Glance

Title A Tale of Two SOCs: Insights From Two Red Team Assessments
Original Publication  August 25, 2026
Executive Summary

The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at …

CISA (ALL)
08/25/2026

View CSAF

Summary

SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released …

CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image.

The following versions of PayRange API are affected:

  • PayRange …
CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user.

The following versions of Zoneminder are affected:

  • Zoneminder 1.37.48|1.38.3 
CVSS Vendor Equipment Vulnerabilities
CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation.

The following versions of Ebyte NE2-D11 are affected:

  • NE2-D11 Firmware FW-9167-0-11
CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to access sensitive information and override user permissions.

The following versions of Rently Smart Home are affected:

  • Smart Home <=20.1.0
CVSS Vendor Equipment Vulnerabilities