Johnson Controls Inc. has identified serious vulnerabilities in its Airwall software, specifically affecting versions 4.0.4 and earlier. These flaws could let attackers decrypt sensitive data, bypass authentication, and access unauthorized files on the system. One vulnerability involves a hardcoded cryptographic key that is the same across all installations, making it easier for attackers to exploit. Another allows for arbitrary file read through inadequate validation of user input, potentially exposing sensitive configuration files or credentials. Companies using affected versions are urged to upgrade to version 4.1.0 or later and implement security best practices to mitigate risks.
Articles tagged "CVE"
Found 571 articles
A serious vulnerability has been identified in Johnson Controls' Metasys building automation system, affecting versions 12, 13, 14, and 15. This flaw allows a low-privilege user to inject malicious code into the Metasys user interface via a specially crafted URL. This can enable session hijacking, where attackers could gain unauthorized access to the system as other users, including administrators. Organizations using these affected versions should take immediate action to apply the latest patches or upgrade to version 16.0, which is not impacted by this vulnerability. Without prompt remediation, the risk of exploitation could pose significant security threats to critical infrastructure sectors worldwide, including manufacturing and transportation.
Siemens has identified a serious vulnerability in its Siveillance Video Management Servers that could allow attackers to execute arbitrary code remotely. This flaw, classified as CVE-2026-3014, affects several versions of the software, specifically Siveillance Video V2023 R3 versions prior to 23.3.27, V2024 R1 versions before 24.1.16, and V2025 versions below 25.1.15. Siemens urges users to update their systems to the latest versions to mitigate the risk. The vulnerability poses a significant threat to critical infrastructure sectors, including manufacturing and communications, making it crucial for organizations using these systems to act promptly. Users are also advised to enhance their network security measures to protect against potential exploitation.
A serious vulnerability has been found in the Flow Neuroscience FL-100 devices, which could allow attackers within Bluetooth range to manipulate brain stimulation settings. This issue arises from a hard-coded credential that is shared across all affected units, enabling unauthorized access to bypass authentication. The vulnerability impacts both the Flow Neuroscience FL-100 and Halo Neuroscience FL-100, versions released before July 2026. Users are urged to install the latest firmware updates via the Flow app to mitigate this risk. Given the nature of these devices, which are used in healthcare, the implications for patient safety are significant, making immediate action essential to prevent potential exploitation.
Siemens LOGO! Soft Comfort has been found to have serious vulnerabilities related to project-file encryption and password management. Local attackers can exploit these weaknesses to extract the master key, which would allow them to decrypt project data or eliminate project passwords entirely. Specifically, the software uses a hardcoded AES master key and stores passwords as unsalted SHA-256 hashes, making them susceptible to dictionary and brute-force attacks. Siemens has released an updated version, LOGO! Soft Comfort V9, to address these issues and strongly advises users to upgrade to this version or later. This situation poses a significant risk to sensitive project configurations, particularly in sectors like commercial facilities and transportation systems worldwide.
Recent vulnerabilities have been discovered in the ANDRITZ HIPASE-250 and 250 SCALA systems, affecting versions up to 7.20. These flaws allow attackers to read sensitive data, access workstations, and potentially exploit hard-coded credentials. The vulnerabilities include inadequate password storage, missing authentication for critical functions, and the exposure of sensitive endpoints. Users are urged to update to the latest versions, V8.00.00 or V8.15.00, which address these issues. This situation poses significant risks, particularly for sectors like energy where these systems are deployed globally.
Siemens Solid Edge has been found to have several vulnerabilities related to file parsing, specifically involving DFT, PAR, and PSM files. These vulnerabilities could allow attackers to crash the application or execute arbitrary code, posing a significant risk to users. Affected versions include Solid Edge SE2025 versions prior to 225.0.15 and SE2026 versions before 226.0.7. Siemens has urged users to update to the latest versions to mitigate these risks. This matter is particularly important for organizations in critical manufacturing sectors, as it affects the integrity and security of their operations worldwide.
Siemens has identified two serious vulnerabilities in its Simcenter Femap application, both related to how the software handles BMP file formats. If users open a specially crafted malicious BMP file, it could lead to application crashes or allow attackers to execute arbitrary code. This affects all versions of Simcenter Femap prior to 2606.0001. Siemens has urged users to update to this latest version to mitigate the risks. The vulnerabilities, assigned CVE-2026-59700 and CVE-2026-59701, have a high severity rating of 7.8 on the CVSS scale, making it critical for users to act promptly. The company encourages implementing strong network protections and following its operational guidelines for industrial security.
A serious security vulnerability has been discovered in the Haiwell IoT Cloud HMI Gateway, specifically in version 3.40.1.12. This flaw allows attackers to inject and execute arbitrary operating system commands with root privileges, posing a significant risk to critical infrastructure sectors like energy and water management. The vulnerability stems from improper input handling in the Net Check feature, which fails to sanitize user inputs effectively. Although no active exploitation has been reported yet, organizations using this product should take immediate action to mitigate potential risks. Haiwell has released a patch (version Scada-v3.50.1.19) to address this issue, which users are urged to implement as soon as possible.
All CISA Advisories
A vulnerability has been identified in AVEVA Enterprise SCADA that could allow attackers to manipulate serialized data, potentially leading to code execution during deserialization. This issue affects multiple versions of the software, including Enterprise SCADA 2025 and earlier versions back to 2022. Users are advised to switch from 'Binary Formatter' to 'Json' serialization and to change the 'AcceptBinaryFormattedData' setting to 'false'. Additionally, AVEVA recommends auditing device permissions and ensuring that only trusted users have operator rights. While there are no reports of active exploitation of this vulnerability, organizations are urged to take defensive measures to protect their systems. For detailed remediation steps, users should refer to the relevant knowledge base articles provided by AVEVA.
Hitachi Energy has reported vulnerabilities affecting its APM Edge product, specifically versions 6.10 and earlier. These vulnerabilities, identified as CVE-2026-43284 and CVE-2026-43500, could allow local unprivileged users to escalate their privileges to root. The flaws stem from issues in the Linux kernel's handling of network packets, which could lead to unauthorized access to critical system binaries. This poses significant risks to the confidentiality, integrity, and availability of the affected systems, particularly in the energy sector where APM Edge is deployed globally. Users are advised to disable certain kernel modules to mitigate these risks while further remediation steps are being evaluated.
A serious vulnerability in VMware's vCenter software has been identified, tracked as CVE-2026-59310. This directory traversal flaw allows remote attackers to execute arbitrary code on affected systems, posing a significant risk to users. Organizations that rely on vCenter for managing virtualized environments should prioritize addressing this issue. The potential for exploitation means that attackers could gain control over systems, leading to data breaches or other malicious activities. It's crucial for companies to apply any available patches or updates to safeguard their infrastructure.
Security Affairs
A serious vulnerability in SharePoint, identified as CVE-2026-55040, is currently being exploited by attackers following the release of a public proof-of-concept on August 12. This flaw, which has a CVSS score of 9.1, allows unauthenticated users to impersonate SharePoint administrators, posing a significant risk to organizations using this platform. The vulnerability was patched in July, but the rapid exploitation indicates that many systems may still be vulnerable. Companies using SharePoint need to prioritize applying the latest security updates to protect their environments from unauthorized access. The situation underscores the importance of timely patch management in preventing exploitation.
Help Net Security
Cisco has reported a high-severity vulnerability, designated as CVE-2026-20349, that attackers are using to cause temporary disruptions in the operation of Cisco firewalls. This flaw has been recognized by the Cybersecurity and Infrastructure Security Agency (CISA) and is included in their catalog of known exploited vulnerabilities. US civilian federal agencies are required to address this issue by August 14, 2026. While Cisco's Product Security Incident Response Team (PSIRT) became aware of the active exploitation in August, specific details regarding the attacks have not been disclosed. The urgency for remediation highlights the potential risks to organizations relying on Cisco’s firewall products.
Researchers have identified a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms that could allow hackers to take control of customer accounts. This flaw impacts businesses using these platforms, raising serious concerns for online retailers and their customers. Attackers could exploit this vulnerability to gain unauthorized access to sensitive user information, potentially leading to identity theft and financial fraud. As attempts to exploit this flaw have already been detected, it's crucial for affected users to take immediate action to secure their accounts. The situation underscores the ongoing risks faced by e-commerce platforms and the need for timely software updates.