Výsledky hledání

typ: zranitelnost× v celém archivu zrušit filtry

1790 karet z 1920 položek · strana 29 z 30 CZ · EN/orig

Hvězdička u CVE znamená, že radar to číslo vytáhl z textu článku, ne ze seznamu chyb, který zpráva uvádí — u té zprávy proto neukazuje KEV, EPSS ani CVSS.

38

SPOJENO PŘES CVE WebPros security advisory (AV26-861)

Serial Number: AV26-861Date: August 28, 2026 As of August 27, 2026, WebPros is affected by vulnerabilities in the following products: cPanel & WebHost Manager (WHM) software Prior to 11.110.0.141 Prior to 11.134.0.53 Prior to 11.136.0.37 Prior to 11.138.0.2 Prior to WP2: 11.138.1.7 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available Security: CVE-2026-65643 Vulnerability in cPanel’s Domain Parking…

EPSS 0.01 CVE-2026-65643 WebPros cPanel CA IT FI

tg: zranitelnost

· Cyber Centre Kanada · WebPros security advisory (AV26-861) · CSIRT Itálie (ACN) · Rilevata vulnerabilità in prodotti cPanel · NCSC-FI · Vulnerability in cPanel’s Domain Parking Functionality

SPOJENO PŘES CVE Grafana security advisory (AV26-860)

Serial Number: AV26-860Date: August 28, 2026 As of August 27, 2026, Grafana is affected by a vulnerability in the following product: Alloy Prior to or equal to 1.18.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Grafana: The open and composable observability platform | Grafana Labs CVE-2026-19516 CVE Record

EPSS 0.00 CVE-2026-19516 Grafana CA IT

tg: zranitelnost

· Cyber Centre Kanada · Grafana security advisory (AV26-860) · CSIRT Itálie (ACN) · Sanata vulnerabilità in Grafana MCP Server

Redis security advisory (AV26-859)

Serial Number: AV26-859Date: August 28, 2026 As of August 27, 2026, Redis is affected by a vulnerability in the following product: Redis 8.0 All except 8.10.1 All except 8.2.9 All except 8.4.6 All except 8.6.6 All except 8.8.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Fix use-after-free in tlsProcessPendingData() pending-list iteration GitHub Releases

Redis CA

tg: zranitelnost

· Cyber Centre Kanada · Redis security advisory (AV26-859)

PaperCut security advisory (AV26-858)

Serial number: AV26-858Date: August 28, 2026 As of August 27, 2026, PaperCut is affected by vulnerabilities in the following products: PaperCut MF Prior to v24 Emergency Patch Release 2 Prior to v25 Emergency Patch Release 2 Prior to v26 Emergency Patch Release 2 PaperCut NG Prior to v24 Emergency Patch Release 2 Prior to v25 Emergency Patch Release 2 Prior to v26 Emergency Patch Release 2 The Cyber Centre encourages users and administrators to review the provided web link and apply any…

PaperCut CA

tg: zranitelnost

· Cyber Centre Kanada · PaperCut security advisory (AV26-858)

ServiceNow security advisory (AV26-857)

Serial number: AV26-857Date: August 28, 2026 As of August 27, 2026, ServiceNow is affected by vulnerabilities in the following products: Xanadu Versions prior to Patch 11 Hot Fix 7a Yokohama Versions prior to Yokohama Patch 12 Hot Fix 3b Versions prior to Yokohama Patch 13 Hot Fix 4 Zurich Multiple versions Australia Multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. August 2026 CVE…

ServiceNow CA

tg: zranitelnost

· Cyber Centre Kanada · ServiceNow security advisory (AV26-857)

NCSC-2026-0334 [1.00] [M/H] Kwetsbaarheden verholpen in PaperCut MF en PaperCut NG van PaperCut

PaperCut heeft kwetsbaarheden verholpen in PaperCut MF en PaperCut NG. Een ongeauthenticeerde kwaadwillende kan de kwetsbaarheden mogelijk achtereenvolgens misbruiken om een PaperCut-omgeving over te nemen en hierop willekeurige code uit te voeren. Hiertoe dient de kwaadwillende malafide netwerkverkeer naar de kwetsbare PaperCut-omgeving te sturen.

PaperCut NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0334 [1.00] [M/H] Kwetsbaarheden verholpen in PaperCut MF en PaperCut NG van PaperCut

[Control Systems] National Instruments security advisory (AV26-856)

Serial Number: AV26-856Date: August 28, 2026 As of August 25, 2026, National Instruments is affected by vulnerabilities in the following product: LabVIEW Prior to 23.0.0 Prior to 23.3.10 Prior to 24.3.7 Prior to 25.3.5 Prior to 26.3.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Memory Corruption Vulnerabilities in NI LabVIEW - NI Integer Conversion Vulnerability Resulting in an Out of Bounds Read…

National Instruments výroba a průmysl energetika vodárenství telekomunikace CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] National Instruments security advisory (AV26-856)

Rilevate vulnerabilità in prodotti MongoDB

Rilevate molteplici vulnerabilità, tra cui 6 con gravità “alta”, in varie librerie client per MongoDB. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato la modifica non autorizzata di dati o codice e la compromissione della disponibilità del servizio sui sistemi interessati.

EPSS 0.00 CVE-2026-75159 CVE-2026-81521 CVE-2026-81522 CVE-2026-81525 CVE-2026-81526 CVE-2026-81529 MongoDB IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Rilevate vulnerabilità in prodotti MongoDB

NCSC-2026-0333 [1.00] [M/H] Kwetsbaarheden verholpen in CodeMeter Runtime van Wibu-Systems

Wibu-Systems heeft meerdere kwetsbaarheden verholpen in CodeMeter Runtime. De kwetsbaarheden bevinden zich in verschillende onderdelen van CodeMeter Runtime, met name in versies voor 8.41a en 9.10. Een lokale aanvaller kan misbruik maken van onjuiste verificatie van NTFS reparse points bij het aanmaken van tijdelijke bestanden door cmu.exe, wat kan leiden tot het verwijderen van willekeurige systeembestanden met System-privileges en daarmee lokale privilege-escalatie. Daarnaast bevat de…

EPSS 0.00 CVE-2026-81573 Wibu-Systems NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0333 [1.00] [M/H] Kwetsbaarheden verholpen in CodeMeter Runtime van Wibu-Systems

ServiceNow warns of three max severity security vulnerabilities

ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. [...]

CVE-2024-4879 * CVE-2024-5178 * CVE-2024-5217 * CVE-2026-18885 * CVE-2026-18886 * CVE-2026-6875 * CVE-2026-6876 * CVE-2026-74820 * ServiceNow US

tg: zneužíváno tg: zranitelnost

· BleepingComputer · ServiceNow warns of three max severity security vulnerabilities

SPOJENO PŘES CVE PaperCut NG/MF Critical Zero-Day Exploited in the Wild

Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the time of writing, the vulnerability has not been assigned a CVE identifier, and PaperCut has not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details…

KEV ✓ · ransomware EPSS 1.00 CVE-2023-27350 PaperCut Software PaperCut školství výroba a průmysl US

tg: zneužíváno tg: zranitelnost tp: malware

· Rapid7 · PaperCut NG/MF Critical Zero-Day Exploited in the Wild · BleepingComputer · PaperCut warns of NG, MF flaw exploited in zero-day attacks

Sanata vulnerabilità in Grafana Alloy

Rilasciati aggiornamenti di sicurezza per risolvere una vulnerabilità con gravità “alta” presente in Grafana Alloy, agente open source per la raccolta ed elaborazione di dati di osservabilità e monitoraggio. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un utente malintenzionato di accedere ad informazioni sensibili sui sistemi interessati.

EPSS 0.00 CVE-2026-75889 Grafana IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Sanata vulnerabilità in Grafana Alloy

Aggiornamenti di sicurezza per prodotti Synology

Aggiornamenti di sicurezza sanano una vulnerabilità con gravità "critica" presente in Synology Chat Server, componente del prodotto DiskStation Manager (DSM) di Synology. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un utente autenticato remoto di leggere o scrivere file arbitrari e compromettere la disponibilità del sistema.

EPSS 0.00 CVE-2026-40541 Synology IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Aggiornamenti di sicurezza per prodotti Synology

Risolta vulnerabilità in Siemens Element Maps

Aggiornamenti di sicurezza Siemens sanano una vulnerabilità con gravità "alta" presente in Element Maps, libreria open source per la visualizzazione di mappe interattive. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un utente non autenticato remoto di iniettare codice arbitrario nella sessione del browser sul sistema target.

EPSS 0.00 CVE-2026-66155 Siemens IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolta vulnerabilità in Siemens Element Maps

SPOJENO PŘES CVE Aggiornamenti di sicurezza sanano molteplici vulnerabilità in ServiceNow

Rilasciati aggiornamenti di sicurezza che sanano 4 vulnerabilità ,di cui una con gravità "alta" e 3 con gravità "critica", presenti nella piattaforma ServiceNow. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un attaccante non autenticato di eseguire codice arbitrario, manipolare dati delle istanze e ottenere privilegi elevati sui sistemi interessati.

EPSS 0.00 CVSS 10.0 CVE-2026-18885 CVE-2026-18886 CVE-2026-6876 CVE-2026-74820 ServiceNow IT FI

tg: zranitelnost

· CSIRT Itálie (ACN) · Aggiornamenti di sicurezza sanano molteplici vulnerabilità in ServiceNow · NCSC-FI · ServiceNow - ServiceNow AI platform vulnerabilities

Risolte vulnerabilità in prodotti WatchGuard

Aggiornamenti di sicurezza sanano numerose vulnerabilità, tra cui 5 con gravità "critica" e 12 con gravità “alta”, in prodotti WatchGuard. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato di eludere i meccanismi di autenticazione, eseguire codice arbitrario e/o compromettere la disponibilità del servizio sui sistemi interessati.

EPSS 0.01 CVE-2026-13086 CVE-2026-13108 CVE-2026-19313 CVE-2026-19314 CVE-2026-19315 CVE-2026-19316 CVE-2026-19317 CVE-2026-19318 CVE-2026-78008 CVE-2026-78009 CVE-2026-78010 CVE-2026-78011 CVE-2026-78174 CVE-2026-78610 CVE-2026-78612 CVE-2026-78613 CVE-2026-78614 WatchGuard IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità in prodotti WatchGuard

1

5

Murrelektronik: Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches

[VDE-2026-061] An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been…

EPSS 0.00 CVE-2026-8173 Murrelektronik výroba a průmysl DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Murrelektronik: Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches

Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities

[VDE-2026-083] Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execution vulnerability. IE-SR-2TX-WL-4G routers are also affected by a SMS password authorization bypass vulnerability. Weidmueller has released new firmware versions of the affected products to fix the vulnerabilities.

EPSS 0.01 CVE-2026-63586 CVE-2026-63587 Weidmüller DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities

SPOJENO PŘES CVE Hackers target WordPress sites in miniOrange auth bypass attacks

Classification: Severe, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 9.8, CVEs: CVE-2026-61979, CVE-2026-15981, Summary: The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication. Because the miniOrange SAML SSO plugin accepts the signature algorithm from incoming SAML responses instead of enforcing the configured one, an attacker can leverage CVE-2026-61979 to select…

EPSS 0.01 CVSS 9.8 CVE-2026-15981 CVE-2026-61979 WordPress miniOrange FI US

tg: varování tg: zneužíváno tg: zranitelnost tp: identita

· NCSC-FI · Hackers target WordPress sites in miniOrange auth bypass attacks · BleepingComputer · Hackers target WordPress sites in miniOrange auth bypass attacks

miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-77995, Summary: Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.

EPSS 0.00 CVSS 10.0 CVE-2026-77995 Joomla miniOrange FI

tg: zranitelnost tp: identita

· NCSC-FI · miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0

SPOJENO PŘES CVE CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection across Windows environments, and Qualys TruRisk Eliminate offers a mitigation that teams can apply now, with…

EPSS 0.11 CVE-2026-50656 CVE-2026-69414 Microsoft US

tg: zranitelnost tg: rozbor tg: propagace

· Qualys · CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

1

SPOJENO PŘES CVE [Control Systems] CISA security advisory (AV26-841)

Serial Number: AV26-841Date: August 21, 2026 As of August 18, 2026, Malcolm is affected by vulnerabilities in the following product: Malcolm Prior to 26.06.1 (CVE-2026-55676) Prior to 26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177) Prior to or equal to 26.07.1 (CVE-2026-19670, CVE-2026-19671) The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CISA Malcolm | CISA ICS Advisories | CISA

EPSS 0.00 CVSS 8.8 CVE-2026-19670 CVE-2026-19671 CVE-2026-55676 CVE-2026-63133 CVE-2026-63134 CVE-2026-63177 CISA CA US

tg: zranitelnost

· Cyber Centre Kanada · [Control Systems] CISA security advisory (AV26-841) · CISA Advisories · CISA Malcolm

2

SPOJENO PŘES CVE CISA warns of hackers exploiting critical MLflow vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]

KEV ✓ EPSS 0.16 CVE-2026-64849 MLflow veřejná správa US CA

tg: zneužíváno tg: zranitelnost tg: regulace

· BleepingComputer · CISA warns of hackers exploiting critical MLflow vulnerability · Cyber Centre Kanada · MLflow security advisory (AV26-832) · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · MLflow Server-Side Request Forgery Vulnerability (CVE-2026-64849)

Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

[VDE-2026-078] Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.

EPSS 0.01 CVE-2026-14946 CVE-2026-14947 CVE-2026-14948 CVE-2026-14949 CVE-2026-14950 CVE-2026-14951 CVE-2026-14952 CVE-2026-14953 Frauscher Sensortechnik doprava DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

1

Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

[vde-2025-056] This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.

EPSS 0.01 CVE-2025-41769 CVE-2025-41770 CVE-2025-41771 Phoenix Contact DE

tg: zranitelnost tg: novinka v produktu tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

1

Multiples vulnérabilités dans Roundcube (10 août 2026)

De multiples vulnérabilités ont été découvertes dans Roundcube. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une falsification de requêtes côté serveur (SSRF).

EPSS 0.01 CVE-2026-74997 CVE-2026-74998 CVE-2026-74999 CVE-2026-75000 CVE-2026-75002 CVE-2026-75004 CVE-2026-75006 CVE-2026-75007 CVE-2026-75010 Roundcube FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Roundcube (10 août 2026)

1

1

Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

[PPSA-2026-003] The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.

KEV ✓ EPSS 1.00 CVE-2026-31431 CVE-2026-43284 CVE-2026-46300 Pilz výroba a průmysl DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

3

SPOJENO PŘES CVE Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2, >= 8.0, < 8.0.5.1, and >= 8.1, < 8.1.3.1. Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.Our…

EPSS 0.28 CVSS 9.5 CVE-2026-66066 Ruby on Rails US IT

tg: zranitelnost tg: novinka v produktu

· Rapid7 · Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066) · CSIRT Itálie (ACN) · Rilevata vulnerabilità in Ruby on Rails

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…

KEV ✓ · ransomware EPSS 0.87 CVSS 9.8 CVE-2026-20316 CVE-2026-42897 CVE-2026-59309 CVE-2026-59310 CVE-2026-59726 CVE-2026-63077 CVE-2026-66066 Cisco Broadcom JetBrains Microsoft vodárenství finance zdravotnictví telekomunikace IL

tg: incident tg: zranitelnost tg: přehled tp: phishing tp: únik dat tp: AI tp: průmyslové systémy

· Check Point Research · 3rd August – Threat Intelligence Report

2

Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

[VDE-2026-008] Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.

Phoenix Contact energetika doprava DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

SPOJENO PŘES CVE ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-41032.

EPSS 0.00 CVSS 6.5 CVE-2026-41032 Phoenix Contact US DE

tg: zranitelnost tp: průmyslové systémy

· Zero Day Initiative · ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability · CERT@VDE · Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers

1

CODESYS PROFINET Controller - Out-of-bounds Write

[Advisory2026-06_VDE-2026-041] CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. The vulnerability in the CODESYS PROFINET Controller is caused by an out‑of‑bounds write during the processing of received invalid PROFINET communication data. Triggering…

EPSS 0.00 CVE-2026-35226 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS PROFINET Controller - Out-of-bounds Write

2

SPOJENO PŘES CVE ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

[VDE-2026-076] The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.

EPSS 0.03 CVE-2025-68160 CVE-2025-69418 CVE-2025-69419 CVE-2025-69420 CVE-2025-69421 CVE-2026-14167 CVE-2026-14168 CVE-2026-14169 CVE-2026-14171 CVE-2026-22795 CVE-2026-22796 CVE-2026-2291 CVE-2026-40510 CVE-2026-4893 CVE-2026-5172 ads-tec Industrial IT Weidmüller DE

tg: zranitelnost tg: novinka v produktu tp: průmyslové systémy

· CERT@VDE · ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

1

Lenze: Incorrect signature validation in the enable SSH routine

[VDE-2026-077] The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.

EPSS 0.00 CVE-2026-14837 Lenze výroba a průmysl DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Lenze: Incorrect signature validation in the enable SSH routine