Summary
Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.
The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected:
- UA-LDS-Installers <1.04.420 (CVE-2026-77477)
| … |
|---|
CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing …
Summary
Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover.
The following versions of Rockwell Automation 1756-ENBT Module are affected:
- 1756-ENBT module vers:all/* (CVE-2025-10478)
| CVSS | Vendor | Equipment | … |
|---|
Summary
Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.
The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected:
- TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684)
Summary
Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.
The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected:
- TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985) …
Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create …
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability
- CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- CVE-2026-49869 Kestra OSS OS …