Bulletins

CISA (ALL)
09/10/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session.

The following versions of AVEVA Pipeline Integrity Monitor are affected:

  • AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513 (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824)
CISA (ALL)
09/10/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.

The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected:

  • Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
CISA (ALL)
09/10/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition.

The following versions of NextGen Healthcare Mirth Connect are affected:

  • Mirth Connect <=v4.7.1 (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578)
CVSS Vendor
CISA (ALL)
09/10/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition.

The following versions …

CISA (ALL)
09/08/2026

Executive summary

China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI …

CISA (ALL)
09/08/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to take full control of the device.

The following versions of CareCam Pro IP Cameras are affected:

  • ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083)
CVSS Vendor Equipment
SIEMENS CERT
09/08/2026
A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user’s session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim’s Teamcenter session. Siemens …
SIEMENS CERT
09/08/2026
Multiple vulnerabilities has been identified in Siemens SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs that can allow an authenticated attacker to alter the secure boot and password configurations. Siemens has released new versions of BIOS for several affected products and recommends to update to the latest versions. Siemens …