Bulletins

CISA (ALL)
08/06/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data.

The following versions of ABB Ability Zenon are affected:

  • IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* 
CISA (ALL)
08/04/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results.

The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected:

  • Applied Biosystems 3500/3500xL Series Data Collection …
CISA (ALL)
08/04/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations.

The following versions of Acrisure KARR BT and DR-100 are affected:

  • KARR BT firmware <July_20_2026
  • DR-100 firmware <July_20_2026
CVSS
CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device.

The following versions of MZ Automation GmbH libiec61850 are affected:

  • libiec61850 <1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360)
CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.

The following versions of Johnson Controls OpenBlue Employee are affected:

  • OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497)
CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.

The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module are affected:

  • ControlLogix 5580 >=V36|<=V37 (CVE-2026-9636)
  • CompactLogix 5380 >=V36|<=V37 (CVE-2026-9636)
  • GuardLogix 5580 …
CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources.

The following versions of Toptech Systems RCU II+ and Multiload II+ are affected:

  • RCU II+ <2025-11-24 (CVE-2026-12562)
CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic.

The following versions of MikroTik RouterOS are affected:

  • RouterOS …