Bulletins

CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications.

…

CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.

The following versions of Xiiaozet LK100W are affected:

  • LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943)
…
CVSS Vendor Equipment Vulnerabilities
CISA (ALL)
08/27/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems.

The following versions of All-Line Equipment Company Fuel-Boss are affected:

  • Fuel-Boss V1 Standard >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
  • Fuel-Boss V1 Portal >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
  • …
SIEMENS CERT
08/27/2026
The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script …
CISA (ALL)
08/26/2026

Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the …

CISA (ALL)
08/26/2026

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  • CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability
  • CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
  • CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability
  • …
CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control.

The following versions of Bendix EC80 Brake ECU are affected:

  • EC80ESP+ J1708 Z228999
  • EC80ESP+ 6S/6M …
CISA (ALL)
08/25/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation.

The following versions of Ebyte NE2-D11 are affected:

  • NE2-D11 Firmware FW-9167-0-11
…