Articles tagged "Update"

Found 419 articles

Critical
Rockwell Automation Arena

All CISA Advisories

Rockwell Automation's Arena software has several critical vulnerabilities that could allow attackers to execute arbitrary code. These vulnerabilities affect versions up to V17.00.00 and include issues in components like model.exe, expmt.exe, linker.exe, and siman.exe. The problems arise from improper validation of user-supplied data, leading to out-of-bounds writes. Users are urged to update to version V17.00.01 to mitigate the risks. This situation is particularly concerning for sectors involved in critical manufacturing, as the software is used worldwide. No active exploitation of these vulnerabilities has been reported yet, but organizations should remain vigilant.

Read Original
Critical
AutomationDirect Productivity Suite

All CISA Advisories

AutomationDirect's Productivity Suite has several critical vulnerabilities that could be exploited by attackers with local or physical access. These vulnerabilities, affecting versions up to 4.6.2.2, include out-of-bounds writes and reads, which could lead to memory corruption, information disclosure, and system instability. Users are strongly advised to update to version 4.7.0.47 or later to mitigate these risks. In the meantime, AutomationDirect recommends several compensating controls, such as disconnecting affected workstations from external networks and restricting access to authorized personnel only. The vulnerabilities affect critical manufacturing sectors worldwide, emphasizing the need for immediate attention from users of the software.

Read Original

A vulnerability has been identified in NASA's Core Flight System (cFS) Health & Safety (HS) Application, specifically affecting versions prior to 7.0.1. This flaw allows attackers to cause the application to crash when processing certain telemetry requests, resulting in a denial-of-service condition. The vulnerability, categorized as CVE-2026-15352, poses a risk to critical infrastructure, particularly in the transportation sector, as the application is used globally. Users are urged to update to version 7.0.1 to mitigate this risk. While there have been no reports of the vulnerability being actively exploited in the wild, organizations are advised to take precautionary measures to secure their systems against potential attacks.

Read Original

Splunk and Zoom have recently patched critical vulnerabilities in their software that could enable attackers to gain unauthorized access to user credentials and data. These flaws could allow malicious actors to take over accounts and escalate their privileges within the affected systems. Users of both platforms should take this update seriously, as the potential for exploitation poses significant security risks. The vulnerabilities were identified in the software's earlier versions, so it is crucial for users to update to the latest versions to protect their information. Prompt action can help prevent unauthorized access and maintain the integrity of user accounts.

Read Original
Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug

Security Affairs

Zoom has identified and patched a serious vulnerability in its Windows applications, labeled CVE-2026-53412, which carries a CVSS score of 9.8. This flaw allows attackers to take control of user accounts without needing any authentication, posing a significant risk to users of older versions of the Workplace and Windows VDI Client. The vulnerability primarily affects organizations using these outdated versions, making it essential for them to update promptly. The potential for account takeover could lead to unauthorized access to sensitive information, making this a critical security issue for affected users. Zoom's quick response to fix this vulnerability is crucial to protect its user base from potential exploitation.

Read Original

A vulnerability known as 'PromptFiction' has been addressed, but it had the potential to combine with another flaw, referred to as the 'Claude Flaw', to launch an end-to-end attack on targeted systems. This means that attackers could have exploited these vulnerabilities to send malicious prompts to AI agents, potentially compromising systems that rely on AI for various functions. While the 'PromptFiction' vulnerability has been fixed, the implications of the 'Claude Flaw' highlight ongoing security challenges in AI systems. Companies using AI technologies need to remain vigilant about such vulnerabilities to protect their systems from potential exploitation. It's crucial for organizations to regularly update their security measures and stay informed about emerging threats.

Read Original

Mozilla has rolled out updates for Firefox to fix two serious vulnerabilities that could be exploited by attackers. The flaws, identified as CVE-2026-15718 and CVE-2026-15719, involve issues with JavaScript: WebAssembly and site isolation in the DOM: Navigation component. Mozilla has warned users that exploit code for these vulnerabilities is already available publicly, increasing the urgency for users to update. It’s crucial for Firefox users to install these updates promptly to protect against potential attacks that could compromise their security and privacy. Keeping software up to date is a key defense against such risks.

Read Original

Fortinet, Ivanti, and ServiceNow have all issued important patches for various vulnerabilities in their products. A notable issue was found in the ServiceNow AI platform, where a critical security flaw could allow remote attackers to execute arbitrary code. This vulnerability poses a significant risk to users, as it could enable unauthorized access and control over affected systems. Organizations using the ServiceNow platform should act quickly to apply the available updates to protect against potential exploitation. The situation serves as a reminder for companies to regularly update their software to mitigate risks from such vulnerabilities.

Read Original

Siemens, Schneider Electric, and Rockwell Automation have addressed numerous vulnerabilities in their industrial control system (ICS) products. These fixes come as part of the latest ICS Patch Tuesday updates, which also prompted advisories from the Cybersecurity and Infrastructure Security Agency (CISA) and VDE CERT. The vulnerabilities could potentially expose systems to various cyber threats, affecting critical infrastructure and manufacturing sectors. Companies using these ICS products need to ensure they apply the latest patches to mitigate any risks associated with these vulnerabilities. This update is crucial for maintaining the security and integrity of industrial operations.

Read Original

The UK government has updated its National Risk Register to include warnings about the potential severity of cyber-attacks. This update indicates a growing concern over the impact that such attacks could have on critical infrastructure and national security. Officials are urging businesses and public sector organizations to bolster their cybersecurity measures in light of these threats. The register serves as a guide for preparedness and response strategies, emphasizing the need for vigilance against increasingly sophisticated cyber threats. This move underscores the importance of being proactive in cybersecurity, as attackers are constantly evolving their tactics.

Read Original

SonicWall has issued a warning about two vulnerabilities in its SMA1000 series, identified as CVE-2026-15409 and CVE-2026-15410. These flaws are being actively exploited by attackers in zero-day attacks, meaning they are being targeted before a fix has been widely implemented. As such, SonicWall is urging all users of the SMA1000 series to apply the newly released security updates to protect against these threats. Failure to patch could leave systems vulnerable to unauthorized access and potential data breaches. Users should prioritize this update to maintain the security of their networks.

Read Original
Critical
ABB T-MAC Plus

All CISA Advisories

ABB has identified multiple vulnerabilities in its T-MAC Plus version 4.0-24 software, which could allow attackers to exploit the system in various ways. These vulnerabilities include issues like file disclosure, broken access controls, cross-site scripting (XSS), and an insecure network protocol that could lead to denial-of-service attacks. Affected users are urged to update to version 4.0-25, which contains fixes for these issues. The vulnerabilities are considered serious, with CVSS scores ranging from 7.4 to 9.9, indicating that they pose significant risks to security. Companies using this software should prioritize applying the update to protect their systems from potential exploitation.

Read Original

Rockwell Automation's 1715-AENTR EtherNet/IP Adapter has a serious vulnerability (CVE-2026-10577) affecting versions up to 3.003. This flaw exposes a debug port that lacks proper authentication controls, allowing attackers to gain unauthorized access to critical functions. If exploited, they could read or delete files, halt tasks, modify memory, and alter I/O states, threatening the device's confidentiality, integrity, and availability. This vulnerability is particularly concerning as it impacts sectors like energy and manufacturing, where security is crucial. Users are advised to upgrade to version 3.011 or later to mitigate the risks associated with this vulnerability.

Read Original
High
ABB Ability Edgenius

All CISA Advisories

ABB has identified a vulnerability, CVE-2026-31431, in its ABB Ability Edgenius platform, which affects versions 3.2.0.0 to 3.2.4.0. This vulnerability is linked to a flaw in the Linux kernel's cryptographic interface that could allow a locally authenticated user to gain elevated privileges, potentially leading to full control of the system. While there have been no reports of this vulnerability being exploited in the wild, ABB recommends that users update to version 3.2.4.1 to mitigate the risk. Users should also limit access to their systems to enhance security. This incident underscores the importance of timely software updates and access controls in protecting against potential exploits.

Read Original
Critical
ABB Advant Master Online Builder

All CISA Advisories

ABB has identified a vulnerability in its Advant Master Online Builder products that could allow unauthorized code execution due to improper handling of search paths for loading dynamic link libraries (DLLs). Affected versions include Control Builder A versions up to 1.4/4 and multiple iterations of 800xA for Advant Master. To mitigate the risk, ABB has released updates that resolve the vulnerability, advising users to upgrade to specific patched versions. Importantly, the vulnerability requires physical access to the system, which limits its exploitability. However, users are still urged to manage access strictly and enforce strong security practices to prevent potential exploitation.

Read Original
PreviousPage 12 of 28Next