Bulletins

CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.

The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected:

  • TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985)
  • …
CISA (ALL)
09/03/2026

View CSAF

Summary

Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control …

CISA (ALL)
09/03/2026

View CSAF

Summary

Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.

The following versions of Rockwell Automation ControlFLASH are affected:

  • ControlFLASH <=V15.07 …
SIEMENS CERT
09/03/2026
Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.
CISA (ALL)
09/02/2026

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.  

  • CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability 
CISA (ALL)
09/02/2026

Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create …

CISA (ALL)
09/01/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution.

The following versions of Rockwell Automation Historian ME are affected:

  • Series B 5.202 (CVE-2025-12768, CVE-2026-12661)
  • Series C 7.101 (CVE-2025-12768, CVE-2026-12661)
…
CISA (ALL)
09/01/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product.

The following versions of Rockwell Automation RSLinx Classic are affected:

  • RSLinx Classic <=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625)
…
CVSS