Bulletins

CISA (ALL)
07/28/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access.

The following versions of MikroTik RouterOS and Cloud Hosted Router are affected:

  • RouterOS vers:all/* (CVE-2026-16347)
  • Cloud Hosted Router vers:all/* (CVE-2026-16347)
CISA (ALL)
07/28/2026

View CSAF

Summary

OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. …

CISA (ALL)
07/28/2026
CI Fortify – Advice for isolating vital systems

CISA and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation and international partners, released joint guidance CI Fortify – Advice for isolating vital systems. This guidance contains practical steps for critical …
CISA (ALL)
07/28/2026

View CSAF

Summary

ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully …

CISA (ALL)
07/23/2026

View CSAF

Summary

Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.

The following versions of Johnson Controls XAAP Android are affected:

  • XAAP Android <1.53
CVSS Vendor Equipment Vulnerabilities
CISA (ALL)
07/23/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.

The following versions of MZ Automation libIEC61850 are affected:

  • libIEC61850 >=v1.0.0|<=v1.6.1 
CISA (ALL)
07/23/2026

View CSAF

Summary

Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service.

The following versions of MZ Automation lib60870 are affected:

  • lib60870 <=2.4.0
CVSS Vendor Equipment
CISA (ALL)
07/23/2026

Executive summary 

A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian …