Bulletins

CISA (ALL)
07/23/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.

The following versions of Weintek cMT3092X are affected:

  • cMT3092X firmware <20210218 
  • EasyWeb <v2.1.20
CVSS
CISA (ALL)
07/23/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling.

The following versions of Panduit IntraVUE are affected:

  • IntraVUE <=3.2.1a14 
CISA (ALL)
07/23/2026

Executive summary 

A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian …

CISA (ALL)
07/23/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.

The following versions of MZ Automation libIEC61850 are affected:

  • libIEC61850 >=v1.0.0|<=v1.6.1 
CISA (ALL)
07/23/2026

View CSAF

Summary

Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.

The following versions of Johnson Controls XAAP Android are affected:

  • XAAP Android <1.53
CVSS Vendor Equipment Vulnerabilities
CISA (ALL)
07/21/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.

The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected:

  • TPDIN-Monitor-WEB2 2.3.9 
CISA (ALL)
07/21/2026

View CSAF

Summary

SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version.

The following versions of …