MB connect line: Multiple SQLi vulnerabilities in mbCONNECT24/mymbCONNECT24
[VDE-2026-044] Multiple vulnerabilities have been discovered in MB connect line mbCONNECT24/mymbCONNECT24.
[VDE-2026-044] Multiple vulnerabilities have been discovered in MB connect line mbCONNECT24/mymbCONNECT24.
[VDE-2026-058] Helmholz: Multiple SQLi vulnerabilities in myREX24V2/myREX24V2.virtual
Helmholz DE
[VDE-2026-045] A vulnerability was discovered in several Endress+Hauser products that can be accessed via ethernet.
EPSS 0.01 CVE-2024-8751 Endress+Hauser DE
[VDE-2026-063] Multiple Murrelektronik network-enabled devices respond to SNMPv2c 'GETBULK' requests with disproportionately large response packets when the requesting party specifies a large max-repetitions value. This response amplification allows the affected devices to be misused as reflectors in distributed denial-of-service (DDoS) attacks against arbitrary third-party victims on the internet.
EPSS 0.05 CVE-2008-4309 Murrelektronik DE
[VDE-2026-066] This update deploys cumulative Microsoft Windows security patches through March 2026 for LTSB 2016, LTSC 2019, and LTSC 2021.
EPSS 0.01 CVE-2026-23673 CVE-2026-25171 CVE-2026-25172 CVE-2026-25174 CVE-2026-25175 CVE-2026-25179 CVE-2026-25181 CVE-2026-25185 CVE-2026-26111 CVE-2026-26128 METTLER TOLEDO Microsoft DE
[VDE-2026-062] Several Murrelektronik devices using Profinet are shipped with the default SNMP community names ('public' for read access and 'private' for write access). If these community strings remain unchanged in the field, an unauthenticated attacker with network access to the device can read its configuration and, depending on the writable OIDs, modify device settings.
EPSS 0.27 CVE-1999-0517 Murrelektronik DE
[Advisory2026-04_VDE-2026-040] CODESYS EtherNet/IP is an add‑on for the CODESYS Development System that provides a fully integrated EtherNet/IP protocol stack along with diagnostic capabilities. A flaw in the EtherNet/IP adapter protocol stack library results in a vulnerability within the generated application code. When an EtherNet/IP adapter is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. Under certain non‑standard operating…
EPSS 0.00 CVE-2026-35225 CODESYS DE
[VDE-2026-031] Certain devices in the WAGO System I/O Field series enable an internal diagnostic capability during the initial stages of system startup. This behavior, which is not part of the publicly documented feature set, briefly allows access to system functions before the main operating environment becomes fully active. Under specific conditions, this could permit interactions with system components that are normally protected during regular operation.
EPSS 0.01 CVE-2026-4769 WAGO DE
Aggiornamenti di sicurezza sanano due vulnerabilità con gravità “critica” in Metabase, piattaforma open source di Business Intelligence (BI). Tali vulnerabilità, qualora sfruttate, consentirebbero a un utente malintenzionato autenticato di eseguire codice arbitrario sui sistemi interessati
EPSS 0.03 CVE-2026-59826 CVE-2026-59827 Metabase IT
[VDE-2026-071] Multiple products from JUMO are affected by webserver vulnerability "CVE-2013-6786, CVE-2014-9222, CVE-2014-9223. This vulnerability leads to DOS of the device by using a misfortune cookie and reflected XSS attacks.
EPSS 0.64 CVE-2013-6786 CVE-2014-9222 CVE-2014-9223 JUMO Allegro DE
[VDE-2026-039] The MBS Universal Gateways (UGW-A-Series, UGW-X-Series) connect devices using various digital communication protocols within the field of building automation. Several security vulnerabilities have been identified in the UGW web GUI and the underlying firmware, affecting version V6_0_0_5 and earlier. Among other things, several CGI methods are affected by insufficient input validation and a lack of bounds checking. These flaws allow authorized attackers to perform arbitrary file…
EPSS 0.00 CVE-2026-35075 CVE-2026-35076 CVE-2026-35077 CVE-2026-35078 CVE-2026-35079 CVE-2026-35080 CVE-2026-35081 CVE-2026-35082 CVE-2026-35083 CVE-2026-35084 CVE-2026-35085 MBS DE
[VDE-2025-067] Motherbox 3 with firmware 1.44 to 1.48 allows an unauthenticated remote attacker read-only access to the internal DB with measurement values from other W&T sensor devices.
EPSS 0.00 CVE-2025-41689 Wiesemann & Theis DE
[VDE-2026-049] Security advisory for Balluff BNI EGW-720-007-K095 and BAV MA-NC-00025-01 firmware versions prior to 2.4.1. This advisory covers multiple vulnerabilities affecting software components used by the device firmware.
Balluff DE
[VDE-2026-046] Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials. It was found that users with no or low rights can access information from devices that should not be available to them. An attacker can use this information to impersonate authorized users.
EPSS 0.00 CVE-2026-3323 VEGA DE
[VDE-2026-070] There is a vulnerability in myREX24V2/myREX24V2.virtual that allows an authenticated remote attacker to access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters.
EPSS 0.01 CVE-2026-10521 Helmholz MB connect line DE
Aggiornamenti di sicurezza sanano una vulnerabilità con gravità “alta” in prodotti TP-Link. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un utente malintenzionato di eseguire codice arbitrario sui sistemi interessati.
EPSS 0.01 CVE-2026-11834 TP-Link IT
[Advisory2026-02_VDE-2026-011] The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups. While only the privileged Administrators and Developer groups are intended to load or debug applications on the controller, users in the restricted Service group are allowed to perform maintenance operations, including explicitly replacing the boot application. In addition to access control, the CODESYS Control runtime system includes an optional application…
EPSS 0.00 CVE-2025-41660 CODESYS DE
[Advisory2026-03_VDE-2026-018] The CODESYS Control runtime system's CmpAuditLog component allows potentially unauthenticated remote attackers to control the format string of processed log messages. Due to the internal processing logic, the impact is limited to a crash of the CODESYS Control runtime.
EPSS 0.00 CVE-2026-3509 CODESYS DE
[Advisory2026-08_VDE-2026-056] The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups including the visualization administrators group, which is intended solely to manage visualization users. Due to insufficient authorization checks an authenticated remote user with low-privileged visualization administrator access can delete higher-privileged accounts. However, independent mechanisms protect the deletion of the last remaining device admin user,…
EPSS 0.00 CVE-2026-8046 CODESYS DE
[Advisory2026-10_VDE-2026-057] The CmpWebServer component in the CODESYS Control Runtime allows users to create browser-based visualizations for monitoring and controlling industrial processes. Due to improper bounds checking, a specially crafted HTTP request from an unauthenticated remote attacker may lead to a size-limited out-of-bounds write, causing a denial of service of the affected device. The CODESYS Control runtime system is only affected if the web server is active, which by default…
EPSS 0.00 CVE-2026-8047 CODESYS DE
[VDE-2026-038] Multiple vulnerabilities have been identified in the TBEN-Lx-SE-M2 firmware prior to version 2.1.2.0 in Managed Ethernet Switches.
EPSS 0.42 CVE-2025-68615 CVE-2026-5416 TURCK DE
Rilasciati gli aggiornamenti di sicurezza di giugno che risolvono 4 nuove vulnerabilità, di cui due con gravità “critica” e due con gravità “alta”, in diversi prodotti Ivanti. Tra queste, si evidenzia la CVE-2026-10520, per la quale risulta disponibile un Proof of Concept (PoC) in rete.
KEV ✓ EPSS 1.00 CVE-2026-10520 Ivanti IT
[VDE-2026-064] Multiple vulnerabilities have been discovered in LabX Standard v21.3.22. Most of the vulnerabilities are fixed in LabX Standard v21.4.23. The Vulnerabilities CVE-2025-69419, CVE-2026-0915, CVE-2025-15467 and CVE-2025-58187 are not yet fixed. The fix will be available in the upcoming releases. Notice: LabX Standard was formerly known as LabX Cloud Local.
EPSS 0.48 CVE-2025-15467 CVE-2025-58187 CVE-2025-69419 CVE-2026-0915 METTLER TOLEDO DE
[VDE-2026-059] Two command injection vulnerabilities have been discovered in Helmholz REX100/REX200/REX250.
EPSS 0.00 CVE-2026-40851 CVE-2026-40852 Helmholz MB connect line DE
[VDE-2026-050] This advisory addresses security issues in PLCnext firmware versions prior to 2026.0.3 that are related to APP handling and the processing of configuration files. The identified vulnerabilities affect APP installation authenticity as well as the handling of configuration data in writable directories. Successful exploitation may allow authenticated attackers with different privilege levels to compromise integrity, availability, and system security of affected PLCnext Control. Both…
EPSS 0.00 CVE-2025-41669 CVE-2025-41670 Phoenix Contact DE
[VDE-2026-053] Titration software versions prior to 2.0.2.6 are affected by libpng vulnerabilities CVE-2026-33416 and CVE-2026-33636.
EPSS 0.01 CVE-2026-33416 CVE-2026-33636 METTLER TOLEDO DE
[Advisory2026-09_VDE-2026-055] Two local privilege escalation vulnerabilities were identified in the CODESYS Development System. Specifically, the PackageManager and the IPM create temporary directories with insecure default permissions when executed with administrative privileges. This allows low-privileged local users to modify a temporary bootstrap file to force the deployment of arbitrary components, or to exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition to replace digitally…
EPSS 0.00 CVE-2026-44468 CVE-2026-44469 CODESYS DE
[VDE-2026-009] A vulnerability in the REST API of the JUMO device allows an attacker to trigger a denial‑of‑service (DoS) condition. Due to an incorrect implementation of the arrayLimit option in the Node.js qs module, limits for incoming request parameters are not properly enforced. As a result, an attacker can send specially crafted requests containing excessively large or deeply nested arrays, causing the web server to become unresponsive. This condition leads to a crash of the web server,…
EPSS 0.00 CVE-2025-15284 JUMO DE
[VDE-2026-043] Multiple vulnerabilities have been discovered in Helmholz myREX24V2/myREX24V2.virtual that could allow RCE, SQLi or information leakage.
EPSS 0.01 CVE-2026-33613 CVE-2026-33614 CVE-2026-33615 CVE-2026-33616 CVE-2026-33617 Helmholz MB connect line DE
[Advisory2026-07_VDE-2026-052] A vulnerability in the CODESYS Visualization login dialog has been identified. During logins within the CODESYS Visualization, authentication data may not be sufficiently isolated when multiple users perform login operations concurrently. As a result, an authenticated visualization user may be able to obtain credentials entered by another visualization user. The issue affects only login operations within an active visualization session and can be triggered via…
EPSS 0.00 CVE-2026-0393 CODESYS DE
[VDE-2024-017] Critical vulnerabilities have been discovered in the product due to outdated software components.The impact of the vulnerabilities on the affected device may result in Denial of service Bypassing of authentication Information disclosure
EPSS 0.80 CVE-1999-0524 CVE-2002-20001 CVE-2004-0230 CVE-2011-3389 CVE-2020-7070 CVE-2021-21707 CVE-2022-31629 CVE-2022-40735 Pepperl+Fuchs DE
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.02 CVSS 7.8 CVE-2026-33835 US
[Advisory2026-05_VDE-2026-042] CODESYS Modbus is an add‑on for the CODESYS Development System that provides a fully integrated Modbus protocol stack along with diagnostic capabilities. A flaw in the CODESYS Modbus TCP Server protocol stack library results in a vulnerability. When a Modbus TCP server is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. The vulnerability is caused by a resource management issue in the Modbus TCP server…
EPSS 0.00 CVE-2026-35227 CODESYS DE
[VDE-2026-005] The Firmware installed on the CR3171 is impacted by various CODESYS vulnerabilities.
EPSS 0.01 CVE-2025-41658 CVE-2025-41659 CVE-2025-41691 ifm CODESYS DE
Google ha rilasciato gli aggiornamenti di sicurezza di maggio per sanare una vulnerabilità con gravità “critica” che interessa il sistema operativo Android. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato su rete locale di eseguire codice arbitrario sul sistema.
EPSS 0.01 CVE-2026-0073 Google Android IT
[PPSA-2026-002] The PASvisu Runtime is affected by a vulnerability in a third-party component which can be exploited by malicious web requests.
EPSS 0.00 CVE-2018-25193 Pilz výroba a průmysl DE
[VDE-2026-029] MX/MR firmware V2.0.0 or earlier is affected by the OpenSSL vulnerability CVE-2025-15467.
EPSS 0.48 CVE-2025-15467 Mettler Toledo OpenSSL DE
[VDE-2026-023] Attacks are possible when installing key files and digitally signed objects. These attacks can only be carried out if these files are uploaded and installed by a logged-in user with high privileges.
EPSS 0.48 CVE-2025-15467 CVE-2025-69419 Phoenix Contact OpenSSL DE
[VDE-2026-015] Vulnerabilities in WALL IE devices with firmware
EPSS 0.96 CVE-2016-2183 Helmholz DE
[VDE-2026-032] The display unit of the Endress+Hauser MCS200HW is affected by a sudo chroot vulnerability.
KEV ✓ EPSS 0.59 CVE-2025-32463 Endress+Hauser DE
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVSS 7.0 CVE-2026-26174 US
[VDE-2024-008] A security vulnerability has been identified in the Web-Based Management (WBM) function when OpenVPN is enabled.
EPSS 0.01 CVE-2024-1490 WAGO DE
[VDE-2025-098] OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap buffer overflow in the event registration parsing code. This allows an attacker to modify the head and potentially execute arbitrary code in the context of the ubus daemon. The affected code is executed before running the ACL checks, all ubus clients are able to send such messages. In addition to the heap corruption, the crafted subscription also results in a…
EPSS 0.00 CVE-2025-62526 Baade M2M-Products OpenWrt DE
[VDE-2025-107] Multiple vulnerabilities in a Qualcomm component have been reported in a closed-source report. This component is an integral part of the radio chip found in several Endress+Hauser products.
[VDE-2026-003] Multiple Endress+Hauser devices are prone to vulnerabilities found in e!Runtime and the CODESYS V3 framework.
EPSS 0.02 CVE-2022-47378 CVE-2022-47379 CVE-2022-47380 CVE-2022-47381 CVE-2022-47382 CVE-2022-47383 CVE-2022-47384 CVE-2022-47385 CVE-2022-47386 CVE-2022-47387 CVE-2022-47388 CVE-2022-47389 CVE-2022-47390 CVE-2022-47391 CVE-2022-47392 CVE-2022-47393 Endress+Hauser DE
Elastic Security Labs is releasing an initial triage and detection rules for the Axios supply-chain compromise. We have released a detailed analysis on the Axios compromise RAT and payloads. Elastic Security Labs filed a GitHub Security Advisory to the axios repository on March 31, 2026 at 01:50 AM UTC to coordinate disclosure and ensure the maintainers and npm registry could act on the compromised versions. Introduction We are currently tracking a supply chain attack involving malicious Axios…
axios US
[VDE-2026-010] Multiple vulnerabilities have been identified in WAGO Solution Builder and WAGO Device Sphere that affect components responsible for authentication and system communication.
EPSS 0.66 CVE-2025-55315 CVE-2026-2328 WAGO DE
[VDE-2026-021] The VC Hub incorporates the Magick.NET‑Q16‑AnyCPU component, derived from ImageMagick, to process user‑uploaded images and generate thumbnails within the projects image library. Only authenticated users with the Design Project Permission can upload images.
WAGO DE
[VDE-2026-025] Multiple vulnerabilities have been discovered in Helmholz myREX24V2 / myREX24V2.virtual that could allow unauthenticated RCE or SQLi.
EPSS 0.01 CVE-2026-32968 CVE-2026-32969 Helmholz MB connect line DE
[VDE-2026-020] A vulnerability has been found affecting the Managed Switches of WAGO. An unauthenticated attacker can fully compromise the device via an undocumented function.
EPSS 0.01 CVE-2026-3587 WAGO DE