Advertisement
CVE-2025-65856: Authentication Bypass in Xiongmai XM530 IP Cameras
Critical authentication bypass (CVE-2025-65856) in Xiongmai XM530 IP Camera firmware allows unauthenticated remote access to video streams and sensitive data.
CVE-2026-27668: Privilege Escalation in Siemens RUGGEDCOM CROSSBOW
Authenticated User Administrators can escalate privileges in Siemens RUGGEDCOM CROSSBOW SAM-P versions prior to 5.8. Update to mitigate CVE-2026-27668 risks.
Silex SD-330AC and AMC Manager RCE via CVE-2026-32956 — Patch Now
Silex Technology devices face critical RCE and DoS risks via 13 vulnerabilities. Critical infrastructure defenders must update to firmware Ver 1.50 immediately.
Securing Serial-to-IP Devices: Mitigating Thousands of OT Bugs
Industrial serial-to-IP converters are riddled with thousands of vulnerabilities, posing a significant risk to legacy infrastructure and OT environments.
CVE-2026-5387: AVEVA Pipeline Simulation Privilege Escalation
Unauthenticated attackers can exploit CVE-2026-5387 in AVEVA Pipeline Simulation <=2025_SP1_build_7.1.9497.6351 to modify critical ICS simulation parameters and training…
ICS Patch Tuesday: 8 Industrial Giants Patch Critical Vulnerabilities
Analysis of new security advisories from Siemens, Schneider Electric, and others regarding critical infrastructure vulnerabilities and remediation steps.
Advertisement
Iranian Actors Target Rockwell PLCs: 4,000 US Devices Exposed
Iranian-linked cyber actors have identified nearly 4,000 exposed US industrial control systems, primarily Rockwell Automation PLCs, raising critical infrastructure…
CVE-2025-13926: Critical Flaw in Contemporary Controls BASC 20T
CISA warns of a CVSS 9.8 vulnerability in Contemporary Controls BASControl20 3.1. Attackers can forge packets to reconfigure or delete PLC components.
Iran-Linked Cyber Attacks Persist Despite Israel-Hezbollah Ceasefire
Iran-affiliated threat actors maintain operational tempo against US critical infrastructure, disregarding kinetic pauses in Middle East regional conflicts.
Iranian Hackers Targeting U.S. Critical Infrastructure via PLCs
U.S. agencies warn of Iran-linked hackers disrupting critical infrastructure by exploiting internet-exposed PLCs to manipulate data and halt operations.
Mitsubishi Electric ICS Vulnerabilities Expose SQL Credentials
High-severity vulnerabilities (CVE-2025-14815, CVE-2025-14816) in Mitsubishi Electric ICS/SCADA products risk SQL credential exposure and data compromise.
Ivanti Connect Secure RCE: Internal Network Vulnerability Detection
Analyze the impact of Ivanti Connect Secure vulnerabilities and learn how to conduct internal network vulnerability scanning for Ivanti appliances to detect flaws.
Yokogawa CENTUM VP CVE-2025-7741 Hardcoded Password Patch Guidance
CISA identifies a hardcoded password in Yokogawa CENTUM VP (CVE-2025-7741). Learn how to secure the PROG account and apply the R7.01.10 patch now.
CVE-2026-3356: Anritsu Remote Spectrum Monitor Authentication Bypass
Critical CVE-2026-3356 allows authentication bypass in Anritsu Remote Spectrum Monitors.
CVE-2026-3587: WAGO Switches CLI Escape Leads to Full Device Compromise
Critical flaw CVE-2026-3587 in WAGO Industrial Managed Switches allows unauthenticated remote attackers to fully compromise devices via CLI escape.
Schneider Electric Plant iT/Brewmaxx RCE via Multiple Redis Vulnerabilities
Multiple critical and high-severity vulnerabilities in Schneider Electric Plant iT/Brewmaxx 9.60+ (Redis component) enable RCE and privilege escalation, affecting…
CVE-2026-2417: Pharos Controls RCE via Missing Authentication
Critical vulnerability (CVE-2026-2417) in Pharos Controls Mosaic Show Controller firmware 2.15.3 allows unauthenticated root RCE. Upgrade to 2.16+ immediately.
CVE-2025-13902: Patching Schneider Electric Modicon Controllers
Schneider Electric Modicon M241 and M251 controllers face XSS risks via CVE-2025-13902. Learn how to patch firmware and secure industrial control networks.
CVE-2026-2273: Schneider Electric EcoStruxure Automation Expert RCE
Schneider Electric has addressed a high-severity code injection vulnerability (CVE-2026-2273) in EcoStruxure Automation Expert that risks full system compromise.
CVE-2025-13957: Hard-coded Credentials in Schneider EcoStruxure DCE
Hard-coded credentials in Schneider Electric EcoStruxure Data Center Expert v9.0 and prior (CVE-2025-13957) allow information disclosure and RCE if SOCKS Proxy is…
ICS Patch Tuesday: Siemens, Schneider, Moxa Fix Critical Flaws
Industrial leaders Siemens, Schneider Electric, Moxa, and Mitsubishi Electric address over 40 vulnerabilities in critical ICS hardware and software components.
CVE-2025-57176: Unauthenticated File Upload in Ceragon Siklu Devices
An unauthenticated file upload vulnerability (CVE-2025-57176) in Ceragon Siklu MultiHaul and EtherHaul series devices poses risks to critical communications…
CVE-2026-3611: Critical Auth Bypass in Honeywell IQ4x BMS Controllers
CISA warns of a critical authentication bypass (CVE-2026-3611) in Honeywell IQ4x BMS Controllers, allowing unauthenticated attackers administrative access and potential…
CVE-2026-3094: Delta CNCSoft-G2 Out-of-bounds Write RCE
Delta Electronics CNCSoft-G2 is vulnerable to an out-of-bounds write (CVE-2026-3094) allowing remote code execution. Update to V2.1.0.39.