Výsledky hledání

sektor: výroba a průmysl v celém archivu

Různé zkratky a hodnoty pod každou zprávou mají svoji legendu — pokud na údaji postojíte myší. Některé jsou klikatelné. Typicky CVE.

zrušit filtry CZ · EN/orig

44 karet z 44 položek

1

CISA Releases Two Industrial Control Systems Advisories

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.8, CVEs: CVE-2026-63133, CVE-2026-63134, CVE-2026-55676, CVE-2026-63177, CVE-2026-19670, CVE-2026-19671, CVE-2026-59086, Summary: CISA released two Industrial Control Systems (ICS) Advisories. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-26-230-01 CISA Malcolm ICSA-26-230-02 Siemens Simcenter Nastran

EPSS 0.00 CVSS 8.8 CVE-2026-19670 CVE-2026-19671 CVE-2026-55676 CVE-2026-59086 CVE-2026-63133 CVE-2026-63134 CVE-2026-63177 Siemens výroba a průmysl FI

NCSC-FI ·

3

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive…

CVSS 7.0 Rapid7 Microsoft veřejná správa zdravotnictví finance výroba a průmysl US

Rapid7 ·

Siemens Simcenter Nastran

View CSAF Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions. The…

EPSS 0.00 CVSS 7.8 CVE-2026-59086 Siemens výroba a průmysl obrana energetika zdravotnictví US

CISA Advisories ·

10

Haiwell IoT Cloud HMI Gateway

View CSAF Summary Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected: Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188) CVSS Vendor Equipment Vulnerabilities v3 10 Haiwell Haiwell IoT Cloud HMI Gateway Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors:…

EPSS 0.02 CVSS 10.0 CVE-2026-19188 Haiwell energetika výroba a průmysl vodárenství US

CISA Advisories ·

Siemens Simcenter Femap

View CSAF Summary Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version. The following versions of Siemens Simcenter Femap are affected: Simcenter…

EPSS 0.00 CVSS 7.8 CVE-2026-59700 CVE-2026-59701 Siemens výroba a průmysl US

CISA Advisories ·

AVEVA Enterprise SCADA

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are affected: Enterprise SCADA 2025 (CVE-2025-7639) Enterprise SCADA >=2024|<=2024_SP1_P01 (CVE-2025-7639) Enterprise SCADA >=2023|<=2023_SP1 (CVE-2025-7639) Enterprise SCADA >=2022|<=2022_SP2_P2 (CVE-2025-7639) Enterprise SCADA <=2021_SP2_P5 (CVE-2025-7639)…

EPSS 0.00 CVSS 7.1 CVE-2025-7639 AVEVA výroba a průmysl energetika US

CISA Advisories ·

Siemens Solid Edge

View CSAF Summary Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Solid Edge are affected: Solid Edge SE2025 vers:intdot/<225.0.15 (CVE-2026-50058, CVE-2026…

EPSS 0.00 CVSS 7.8 CVE-2026-50058 CVE-2026-50059 CVE-2026-50060 CVE-2026-50061 CVE-2026-50062 CVE-2026-50063 CVE-2026-50064 Siemens výroba a průmysl US

CISA Advisories ·

Siemens LOGO! Soft Comfort

View CSAF Summary Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive…

EPSS 0.00 CVSS 6.8 CVE-2026-57262 CVE-2026-57263 Siemens výroba a průmysl doprava US

CISA Advisories ·

Siemens Siveillance Video

View CSAF Summary Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Siveillance Video are affected: Siveillance Video V2023 R3 vers:intdot/<23.3.27 (CVE-2026-3014) Siveillance Video V2024 R1 vers:intdot/<24.1.16 (CVE-2026-3014) Siveillance Video V2025 vers:intdot/<25.1.15 (CVE-2026-3014) CVSS…

EPSS 0.01 CVSS 9.1 CVE-2026-3014 Siemens výroba a průmysl telekomunikace US

CISA Advisories ·

Johnson Controls Metasys

View CSAF Summary Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access. The following versions of Johnson Controls Metasys are affected: Metasys 12 vers:all/* (CVE-2026-34491) Metasys 13 vers:all/* (CVE-2026-34491) Metasys 14 Metasys 15 CVSS Vendor…

CVSS 8.0 CVE-2026-34491 Johnson Controls energetika výroba a průmysl veřejná správa doprava US

CISA Advisories ·

Johnson Controls Inc. Airwall

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources. The following versions of Johnson Controls Inc. Airwall are affected: Airwall <=4.0.4 (CVE-2026-64887, CVE-2026-34492) CVSS Vendor Equipment Vulnerabilities v3 6.8 Johnson Controls Inc. Johnson Controls Inc. Airwall Use of…

EPSS 0.00 CVSS 6.8 CVE-2026-34492 CVE-2026-64887 Johnson Controls výroba a průmysl veřejná správa energetika doprava US

CISA Advisories ·

Siemens Desigo DXR and PXC Controllers

View CSAF Summary A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Desigo DXR and PXC Controllers are affected: Desigo DXR2 vers:intdot/<01.21.233.16-7862 …

EPSS 0.00 CVSS 4.3 CVE-2026-59693 Siemens energetika zdravotnictví výroba a průmysl doprava US

CISA Advisories ·

Siemens Parasolid

View CSAF Summary Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Parasolid are affected: Parasolid V38.0 vers:intdot/<38.0.235 (CVE-2026-64629) Parasolid V38.1 vers:intdot/<38.1.230 (CVE…

EPSS 0.00 CVSS 7.8 CVE-2026-64629 Siemens výroba a průmysl US

CISA Advisories ·

2

[Control Systems] Phoenix Contact security advisory (AV26-811)

Serial number: AV26-811Date: August 12, 2026 As of August 12, 2026, Phoenix Contact is affected by vulnerabilities in the following products: AXC F 1152 Prior to 2026.0.3 AXC F 1252 Prior to 2026.0.3 AXC F 2000 EA Prior to 2026.0.3 AXC F 2152 Prior to 2026.0.3 AXC F 3152 Prior to 2026.0.3 BPC 9102S Prior to 2026.0.3 BPC 9202S Prior to 2026.0.3 Catan C1 Prior to 2026.0.3 EPC 1502 Prior to 2026.0.3 EPC 1522 Prior to 2026.0.3 RFC 4072R Prior to 2026.0.3 RFC 4072S Prior to 2026.0.3 VL3 UPC 2440…

Phoenix Contact výroba a průmysl energetika vodárenství CA

Cyber Centre Kanada ·

Siemens RUGGEDCOM APE1808

View CSAF Summary Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures. The following versions of Siemens RUGGEDCOM APE1808 are affected: RUGGEDCOM APE1808 vers:all/* (CVE-2026-23573, CVE-2026-59839) CVSS Vendor Equipment Vulnerabilities v3 6.1 Siemens Siemens RUGGEDCOM APE1808…

EPSS 0.00 CVSS 6.1 CVE-2026-23573 CVE-2026-59839 Siemens Fortinet výroba a průmysl energetika doprava US

CISA Advisories ·

4

[Control systems] Siemens security advisory (AV26-802)

Serial Number: AV26-802Date: August 11, 2026 As of August 11, 2026, Siemens is affected by vulnerabilities in the following products: Desigo DXR2 Prior to V01.21.233.16-7862 Desigo PXC3 Prior to V01.21.233.16-7862 Desigo PXC4 Prior to V02.21.194.36-2715 Desigo PXC5.E003 Prior to V02.21.194.36-2715 Desigo PXC5.E24 Prior to V02.21.194.36-2715 Desigo PXC7 Prior to V02.21.194.36-2715 LOGO! Soft Comfort Prior to V9 Parasolid V38.0 Prior to V38.0.235 Parasolid V38.1 Prior to V38.1.230 SIMATIC IoT2050…

Siemens výroba a průmysl CA

Cyber Centre Kanada ·

Aggiornamenti per prodotti Siemens

Siemens ha rilasciato aggiornamenti di sicurezza per sanare molteplici vulnerabilità nei propri prodotti, di cui 1 con gravità “critica” e 13 con gravità “alta”. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un utente malintenzionato di eseguire codice arbitrario e di leggere file arbitrari sul filesystem dei sistemi interessati.

Siemens výroba a průmysl energetika IT

CSIRT Itálie (ACN) ·

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Overview of the attack In July 2026, Kaspersky experts detected a new attack by the Head Mare group. Previously, we classified them as hacktivists, but now we define them as an APT group due to the sophistication of their TTPs and the absence of destructive activity (encryption, wiping) in the targeted infrastructures. In this latest campaign, the attackers exploited a chain of vulnerabilities in the TrueConf video conferencing server and replaced the original TrueConf client installers with…

TrueConf Kaspersky Microsoft energetika výroba a průmysl doprava telekomunikace RU

Securelist (Kaspersky) ·

Johnson Controls C-CURE 9000 and Victor application server (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor application server (Update A) are affected: C-CURE 9000 <=v3.10.1 (CVE-2026-21655) victor Application Server <=v4.10 (CVE-2026-21655) victor <=v7.0 (CVE-2026-21655) victor Web victor Web <=v7.1 (CVE-2026-34496) CVSS Vendor Equipment Vulnerabilities v3 9.6 Johnson Controls Johnson…

EPSS 0.00 CVSS 9.6 CVE-2026-21653 CVE-2026-21655 CVE-2026-34496 Johnson Controls výroba a průmysl US

CISA Advisories ·

1

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

In this article Pre-encryptionEncryptionPost-encryptionDefending against DeadLock ransomwareIndicators of compromise Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations. Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion…

Microsoft doprava výroba a průmysl energetika US

Microsoft Security Blog ·

3

Johnson Controls Inc. TL280

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device. The following versions of Johnson Controls Inc. TL280 are affected: TL280 <5.63 (CVE-2026-27871) CVSS Vendor Equipment Vulnerabilities v3 4.1 Johnson Controls Inc. Johnson Controls Inc. TL280 Use of a Broken or Risky Cryptographic Algorithm Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and…

EPSS 0.00 CVSS 4.1 CVE-2026-27871 Johnson Controls energetika výroba a průmysl veřejná správa doprava US

CISA Advisories ·

ABB Ability Zenon

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Zenon Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data…

KEV ✓ EPSS 0.83 CVSS 7.8 CVE-2020-7921 CVE-2020-7928 CVE-2025-14847 ABB energetika zdravotnictví vodárenství výroba a průmysl US

CISA Advisories ·

1

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

In this article Attack chain overviewMitigation and protection guidanceIndicators of compromise (IOC)Microsoft Defender XDR detectionsAdvanced hunting queriesLearn more Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including packages associated with major enterprise software ecosystems such as keyv, flat-cache, cache-manager, and others. The malicious releases contain a Mini Shai-Hulud…

Microsoft npm GitHub Amazon Web Services výroba a průmysl US

Microsoft Security Blog ·

4

Kritická zranitelnost v systému Siemens Desigo CC

Společnost Siemens vydala bezpečnostní aktualizace pro systém Desigo CC. Opravy řeší kritickou zranitelnost (CVSS 9.8), jejíž zneužití může umožnit vzdálené spuštění kódu nebo způsobit nedostupnost systému. Zranitelnost se týká organizací využívajících systém Siemens Desigo CC pro řízení budov (Building Management System - BMS). Provozovatelům se doporučuje co nejdříve nainstalovat dostupné bezpečnostní aktualizace a zajistit, aby systémy nebyly přímo dostupné z internetu, ale byly chráněny…

CVSS 9.8 Siemens energetika výroba a průmysl CZ

CSIRT.CZ (CZ.NIC) ·

ZDI-26-502: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44106.

EPSS 0.00 CVSS 7.8 CVE-2026-44106 Phoenix Contact výroba a průmysl US

Zero Day Initiative ·

ZDI-26-516: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability

This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-44090.

EPSS 0.00 CVSS 6.5 CVE-2026-44090 Phoenix Contact výroba a průmysl energetika US

Zero Day Initiative ·

ZDI-26-519: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44099.

EPSS 0.00 CVSS 7.5 CVE-2026-44099 Phoenix Contact výroba a průmysl US

Zero Day Initiative ·

1

Inyección SQL en ERPNext de Frappe

SQL Injection in Frappe's ERPNext Wed, 07/29/2026 - 12:41 Aviso Affected Resources ERPNext: versions prior to 15.111.0 and 16.22.0. Description INCIBE has coordinated the disclosure of a high-severity vulnerability affecting Frappe's ERPNext, an enterprise resource planning system. The vulnerability was discovered by Alejandro Ramos.This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type:CVE-2026-12895: CVSS v4.0: 7.1| CVSS AV:N/AC…

EPSS 0.00 CVSS 7.1 CVE-2026-12895 Frappe výroba a průmysl ES

INCIBE-CERT ·

3

ZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12390.

EPSS 0.00 CVSS 7.8 CVE-2026-12390 AzeoTech výroba a průmysl US

Zero Day Initiative ·

ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12921.

EPSS 0.00 CVSS 7.8 CVE-2026-12921 AzeoTech výroba a průmysl US

Zero Day Initiative ·

1

1

20th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance. Jscrambler, a…

KEV ✓ EPSS 0.96 CVE-2026-15409 CVE-2026-15410 CVE-2026-56155 CVE-2026-56164 CVE-2026-60137 CVE-2026-63030 Microsoft WordPress SonicWall výroba a průmysl finance IL

Check Point Research ·

1

2

ZDI-26-438: Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-6071.

CVSS 7.8 CVE-2026-6071 Rockwell Automation výroba a průmysl US

Zero Day Initiative ·

ZDI-26-439: Fuji Electric Tellus pcid64 Driver Exposed Dangerous Method Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-8108.

EPSS 0.00 CVSS 7.8 CVE-2026-8108 Fuji Electric výroba a průmysl US

Zero Day Initiative ·

1

6th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the network of parent company River Financial Corporation on June 16. The bank found ransomware on portions of its server environment and is assessing whether personal data was accessed or exfiltrated. Indra Group, a Spanish…

KEV ✓ EPSS 0.99 CVSS 9.6 CVE-2024-1212 CVE-2026-46242 CVE-2026-46817 CVE-2026-8037 CVE-2026-8451 Oracle Citrix Progress Check Point finance obrana výroba a průmysl energetika IL

Check Point Research ·

1

1

1

The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape

Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously observed in the country during 2022 and 2023. Cyber Criminals Pivoting Back to Germany Germany…

Google výroba a průmysl US

Mandiant / Google TI ·

1

1