Summary
ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying …
Summary
Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened.
The following versions of Medixant RadiAnt DICOM are affected:
- RadiAnt DICOM <=2025.2
| CVSS | …
|---|
Summary
Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device.
The following versions of Johnson Controls Inc. TL280 are affected:
- TL280 <5.63
| CVSS | Vendor | Equipment | Vulnerabilities |
|---|
Summary
Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data.
The following versions of ABB Ability Zenon are affected:
- IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/*
Summary
Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results.
The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected:
- Applied Biosystems 3500/3500xL Series Data Collection …
Summary
Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations.
The following versions of Acrisure KARR BT and DR-100 are affected:
- KARR BT firmware <July_20_2026
- DR-100 firmware <July_20_2026
| CVSS | … |
|---|
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device.
The following versions of MZ Automation GmbH libiec61850 are affected:
- libiec61850 <1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360)
Summary
Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.
The following versions of Johnson Controls OpenBlue Employee are affected:
- OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497)