Bulletins

CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.

The following versions of Rockwell Automation ControlFLASH are affected:

  • ControlFLASH <=V15.07 …
CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.

The following versions of IXON VPN Client are affected:

  • VPN Client <1.4.7 (CVE-2026-75925)
SIEMENS CERT
09/03/2026
Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.
CISA (ALL)
09/02/2026

Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create …

CISA (ALL)
09/02/2026

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.  

  • CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability 
CISA (ALL)
09/01/2026

View CSAF

Summary

The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected:

  • ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
  • GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
  • CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 …
CISA (ALL)
09/01/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution.

The following versions of Rockwell Automation Historian ME are affected:

  • Series B 5.202 (CVE-2025-12768, CVE-2026-12661)
  • Series C 7.101 (CVE-2025-12768, CVE-2026-12661)
CISA (ALL)
09/01/2026

View CSAF

Summary

The following versions of Rockwell Automation Logix Platform are affected:

  • ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
  • CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
  • GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)