Bulletins

CISA (ALL)
09/22/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device.

The following versions of lwIP TCP/IP Stack MQTT Client Application are affected:

  • MQTT Client Application >=2.0.1|<=2.2.1 (CVE-2026-87121)
CVSS …
CISA (ALL)
09/22/2026

View CSAF

Summary

The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and …

CISA (ALL)
09/22/2026

View CSAF

Summary

A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the …

CISA (ALL)
09/22/2026

View CSAF

Summary

Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system.

The following versions of lwIP (Lightweight IP) are affected:

  • API >=2.0.1|<=2.2.1 (CVE-2026-91018)
…
SIEMENS CERT
09/22/2026
This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.
CISA (ALL)
09/17/2026

View CSAF

Summary

Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk …

CISA (ALL)
09/17/2026

View CSAF

Summary

Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year …

CISA (ALL)
09/17/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware.

The following versions of Bransys ELD are affected:

  • Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960)
  • iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960)
…
CVSS Vendor