Siemens has identified a vulnerability affecting its Desigo DXR and PXC controllers that could enable attackers to initiate denial of service (DoS) conditions by sending malformed BACnet packets. This issue can cause the devices to stop responding to BACnet queries, requiring a reset or reboot for recovery. The affected versions include Desigo DXR2, PXC3, PXC4, PXC5.E003, PXC5.E24, and PXC7, all of which are used across various sectors such as healthcare, energy, and transportation. Siemens has released updated versions to address this vulnerability and strongly urges users to apply these updates to maintain device functionality and security.
Articles tagged "Update"
Found 419 articles
A serious vulnerability has been identified in Johnson Controls' Metasys building automation system, affecting versions 12, 13, 14, and 15. This flaw allows a low-privilege user to inject malicious code into the Metasys user interface via a specially crafted URL. This can enable session hijacking, where attackers could gain unauthorized access to the system as other users, including administrators. Organizations using these affected versions should take immediate action to apply the latest patches or upgrade to version 16.0, which is not impacted by this vulnerability. Without prompt remediation, the risk of exploitation could pose significant security threats to critical infrastructure sectors worldwide, including manufacturing and transportation.
Siemens has identified a serious vulnerability in its Siveillance Video Management Servers that could allow attackers to execute arbitrary code remotely. This flaw, classified as CVE-2026-3014, affects several versions of the software, specifically Siveillance Video V2023 R3 versions prior to 23.3.27, V2024 R1 versions before 24.1.16, and V2025 versions below 25.1.15. Siemens urges users to update their systems to the latest versions to mitigate the risk. The vulnerability poses a significant threat to critical infrastructure sectors, including manufacturing and communications, making it crucial for organizations using these systems to act promptly. Users are also advised to enhance their network security measures to protect against potential exploitation.
Siemens LOGO! Soft Comfort has been found to have serious vulnerabilities related to project-file encryption and password management. Local attackers can exploit these weaknesses to extract the master key, which would allow them to decrypt project data or eliminate project passwords entirely. Specifically, the software uses a hardcoded AES master key and stores passwords as unsalted SHA-256 hashes, making them susceptible to dictionary and brute-force attacks. Siemens has released an updated version, LOGO! Soft Comfort V9, to address these issues and strongly advises users to upgrade to this version or later. This situation poses a significant risk to sensitive project configurations, particularly in sectors like commercial facilities and transportation systems worldwide.
Recent vulnerabilities have been discovered in the ANDRITZ HIPASE-250 and 250 SCALA systems, affecting versions up to 7.20. These flaws allow attackers to read sensitive data, access workstations, and potentially exploit hard-coded credentials. The vulnerabilities include inadequate password storage, missing authentication for critical functions, and the exposure of sensitive endpoints. Users are urged to update to the latest versions, V8.00.00 or V8.15.00, which address these issues. This situation poses significant risks, particularly for sectors like energy where these systems are deployed globally.
Siemens Solid Edge has been found to have several vulnerabilities related to file parsing, specifically involving DFT, PAR, and PSM files. These vulnerabilities could allow attackers to crash the application or execute arbitrary code, posing a significant risk to users. Affected versions include Solid Edge SE2025 versions prior to 225.0.15 and SE2026 versions before 226.0.7. Siemens has urged users to update to the latest versions to mitigate these risks. This matter is particularly important for organizations in critical manufacturing sectors, as it affects the integrity and security of their operations worldwide.
Siemens has identified two serious vulnerabilities in its Simcenter Femap application, both related to how the software handles BMP file formats. If users open a specially crafted malicious BMP file, it could lead to application crashes or allow attackers to execute arbitrary code. This affects all versions of Simcenter Femap prior to 2606.0001. Siemens has urged users to update to this latest version to mitigate the risks. The vulnerabilities, assigned CVE-2026-59700 and CVE-2026-59701, have a high severity rating of 7.8 on the CVSS scale, making it critical for users to act promptly. The company encourages implementing strong network protections and following its operational guidelines for industrial security.
WhatsApp has introduced a new optional feature called 'Scam Alert' that aims to protect users from potential scams. This feature utilizes a local machine learning model to identify and flag messages that may be from scammers. By alerting users about suspicious messages, WhatsApp hopes to enhance security and reduce the risk of falling victim to fraud. This update comes as online scams continue to rise, making it crucial for messaging platforms to provide users with tools to recognize and avoid such threats. Users can opt in to this feature, which underscores WhatsApp's commitment to improving user safety in its messaging environment.
Wireshark has released version 4.6.8 to address 28 security vulnerabilities, with nine of these affecting file parsers that process saved capture files. These vulnerabilities could be exploited simply by opening a maliciously crafted capture file, which means an attacker does not need direct access to the network. The affected file parsers include formats like pcapng, Endace ERF, and several others, specifically on Windows systems. This update is critical for users of Wireshark, as it helps prevent potential exploitation that could compromise sensitive data or system integrity. Users are urged to update to the latest version to mitigate these risks.
Help Net Security
In August 2026, Microsoft released patches addressing over 400 vulnerabilities, including a serious zero-day exploit identified as CVE-2026-68820. This particular flaw is a use-after-free vulnerability affecting the Windows Ancillary Function Driver for WinSock (AFD.sys), which could allow a low-privileged local attacker to gain elevated privileges to the SYSTEM level. This means that attackers with local access could potentially execute malicious applications to take control of affected systems. The urgency of this update is underscored by the fact that the vulnerability is already being exploited in the wild. Users and organizations relying on Windows systems should prioritize applying these updates to mitigate potential risks.
Ivanti has released an update to address vulnerabilities in their Endpoint Manager (EPM) that could allow attackers to exploit systems remotely. These flaws could lead to the leaking of credentials for external SQL connections or even crashing the agent service, potentially disrupting operations for affected organizations. Companies using Ivanti EPM need to prioritize applying this update to safeguard against these security risks. The vulnerabilities underline the importance of keeping software up to date to protect sensitive data and maintain system stability.
Zoom has addressed a serious vulnerability in its software that could allow a participant in a video meeting to execute malicious code on another user’s device via the annotation feature. This flaw, known as CVE-2026-53413, is categorized as a zero-click vulnerability, meaning it does not require any interaction from the victim to be exploited. Discovered by A Security, the issue is part of a broader update where Zoom patched a total of four vulnerabilities. The existence of such a flaw raises significant concerns about user safety and privacy during online meetings, as it could potentially lead to unauthorized access to sensitive information. Users are advised to update their Zoom applications to the latest version to protect themselves from possible exploitation.
Zoom has patched a serious vulnerability that could allow a participant in a meeting to execute code on another attendee's machine without any interaction required—hence the term 'zero-click.' This flaw, linked to Zoom's annotation feature, poses a significant risk, particularly as remote work continues to be prevalent. If exploited, it could lead to unauthorized access or control over devices of unsuspecting users. The company has urged users to update to the latest version to ensure their systems are secure. This incident serves as a reminder of the ongoing security challenges faced by popular communication platforms.
The National Institute of Standards and Technology (NIST) is looking to update its National Vulnerability Database in response to the evolving landscape of cyber threats driven by artificial intelligence. As AI technologies become more integrated into security measures, NIST aims to gather public feedback on how to enhance the database to better address these challenges. This initiative is crucial as it will help ensure that security professionals and organizations have access to timely and relevant information about vulnerabilities that AI might exploit. The modernization effort is a proactive step to keep up with the growing complexity of cyber risks that AI presents, ensuring that the database remains a reliable resource for identifying and managing vulnerabilities.
SAP has rolled out 28 new security notes and updated two others to address vulnerabilities in its software. Among these, four notes focus on critical issues related to code injection and memory corruption. These vulnerabilities could allow attackers to execute arbitrary code or crash systems, posing significant risks to organizations using SAP products. Companies relying on SAP software should prioritize applying these patches to protect their systems and sensitive data from potential exploitation. This update underscores the need for ongoing vigilance in maintaining software security.