Summary
Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.
The following versions of Rockwell Automation ControlFLASH are affected:
- ControlFLASH <=V15.07 …
Summary
Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.
The following versions of IXON VPN Client are affected:
- VPN Client <1.4.7 (CVE-2026-75925)
| … |
|---|
Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create …
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability
- CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- CVE-2026-49869 Kestra OSS OS …
Summary
The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected:
- ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
- GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
- CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 …
Summary
Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution.
The following versions of Rockwell Automation Historian ME are affected:
- Series B 5.202 (CVE-2025-12768, CVE-2026-12661)
- Series C 7.101 (CVE-2025-12768, CVE-2026-12661)
Summary
The following versions of Rockwell Automation Logix Platform are affected:
- ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
- CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
- GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
- …