Bulletins

CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.

The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected:

  • UA-LDS-Installers <1.04.420 (CVE-2026-77477)
CISA (ALL)
09/03/2026

CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing …

CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover.

The following versions of Rockwell Automation 1756-ENBT Module are affected:

  • 1756-ENBT module vers:all/* (CVE-2025-10478)
CVSS Vendor Equipment
CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.

The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected:

  • TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684)
CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.

The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected:

  • TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985)
SIEMENS CERT
09/03/2026
Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.
CISA (ALL)
09/02/2026

Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create …

CISA (ALL)
09/02/2026

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.  

  • CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability