Bulletins

CISA (ALL)
07/21/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.

The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected:

  • TPDIN-Monitor-WEB2 2.3.9 
CISA (ALL)
07/21/2026

View CSAF

Summary

Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.

The following versions of Siemens …

CISA (ALL)
07/21/2026

View CSAF

Summary

Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/

The following …

BOSCH PSIRT
07/21/2026

BOSCH-SA-466086: The GitHub Security Lab has discovered a vulnerability in 7-Zip 26.00 and older: A heap buffer overflow vulnerability (GHSL-2026-140) exists in 7-Zip version 26.00, caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to exploit this issue for arbitrary code execution or …

CISA (ALL)
07/16/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product.

The following versions of Rockwell Automation Flex 5000 Adapter are affected:

  • Flex 5000 Adapter 6.011 (CVE-2026-12659)
CVSS
CISA (ALL)
07/16/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server.

The following versions of Rockwell Automation FactoryTalk DataMosaix are affected:

  • DataMosaix Private Cloud <=8.02 (CVE-2026-9292)
CVSS Vendor
CISA (ALL)
07/16/2026

View CSAF

Summary

Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released …

CISA (ALL)
07/16/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.

The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected:

  • Core Flight System (cFS) Health & Safety (HS) Application