Bulletins

BOSCH PSIRT
08/31/2026

BOSCH-SA-223618: Multiple vulnerabilities including stack-based buffer overflows, heap-based buffer overflows, and out-of-bounds reads have been identified in several Bosch Sensortec software components: the BHI360 SensorAPI, BHI385 SensorAPI, BME690 SensorAPI, and the COINES SDK. Depending on the specific vulnerability, a locally/physically positioned attacker, or a compromised peripheral device (connected via I2C, …

CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.

The following versions of Rockwell Automation OTTO Fleet Manager are affected:

  • OTTO Fleet Manager <=V2.36.2 (CVE-2026-75112)
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications.

CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.

The following versions of Xiiaozet LK100W are affected:

  • LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943)
CVSS Vendor Equipment Vulnerabilities
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems.

The following versions of All-Line Equipment Company Fuel-Boss are affected:

  • Fuel-Boss V1 Standard >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
  • Fuel-Boss V1 Portal >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device.

The following versions of Ebyte NA111-M are affected:

  • NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977)
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product.

The following versions of Mitsubishi Electric Multiple FA Products (Update D) …

CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products.

The following versions of Mitsubishi Electric CNC Series (Update A) are affected:

  • Mitsubishi Electric M800VW (BND-2051W000) <=BB (CVE-2025-2399)