Výsledky hledání

sektor: výroba a průmysl× v celém archivu zrušit filtry

99 karet z 101 položek · strana 1 z 2 CZ · EN/orig

7

SPOJENO PŘES CVE ABB Ability Edgenius

View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete…

KEV ✓ EPSS 1.00 CVSS 7.8 CVE-2026-31431 ABB Linux výroba a průmysl energetika vodárenství US EU AT HU

tg: zneužíváno tg: zranitelnost tg: rozbor tp: průmyslové systémy

· CISA Advisories · ABB Ability Edgenius · Fortinet PSIRT · Linux Kernel Vulnerability copy.fail - CVE-2026-31431 · Elastic Security · Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild · CERT-EU · 2026-005: High Vulnerability in the Linux Kernel ("Copy Fail") · CERT.at · Copy Fail Update #1: Kritische Linux-Kernel-Schwachstelle ermöglicht lokale Root-Rechte · NKI Maďarsko · Riasztás a Linux rendszereket érintő Copy Fail sérülékenységről

Schneider Electric PowerChute Serial Shutdown

View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data. The following versions of Schneider Electric…

EPSS 0.00 CVSS 5.3 CVE-2026-13348 Schneider Electric energetika výroba a průmysl US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Schneider Electric PowerChute Serial Shutdown

Schneider Electric Modicon M340 Controller and Communication Modules

View CSAF Summary Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/, BMXNOR0200H https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/: Modicon M340 X80 Ethernet Communication Modules, BMXNGD0100 https://www.se.com/us/en/product/BMXNGD0100/communication-module-modicon-m580-global-data-service/: M580 Global Data module, BMXNOC0401 https://www.se…

EPSS 0.00 CVSS 7.5 CVE-2025-6625 Schneider Electric energetika vodárenství výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Schneider Electric Modicon M340 Controller and Communication Modules

Schneider Electric NetBotz 5 750/755

View CSAF Summary Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access. The following versions…

EPSS 0.01 CVSS 6.4 CVE-2026-13336 CVE-2026-13337 Schneider Electric výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Schneider Electric NetBotz 5 750/755

Mitsubishi Electric GX Works3 and Motion Control Settings

View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs. The following versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected: Mitsubishi Electric GX Works3 vers:all/* (CVE-2026-15688)…

EPSS 0.00 CVSS 8.8 CVE-2026-15688 Mitsubishi Electric výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Mitsubishi Electric GX Works3 and Motion Control Settings

Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly. The following versions of Mitsubishi Electric CC-Link IE TSN…

EPSS 0.00 CVE-2026-13584 Mitsubishi Electric výroba a průmysl US

tg: zranitelnost tp: DDoS tp: průmyslové systémy

· CISA Advisories · Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.In Japan, The Gentlemen was the most active ransomware group in the first half of 2026.Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less than JPY 1 billion accounting for approximately 80% of the total — an increase of around 13% from the previous year…

EPSS 0.00 CVE-2025-2479 výroba a průmysl US

tg: rozbor tp: ransomware tp: AI

· Cisco Talos · Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

1

SPOJENO PŘES CVE TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.6, CVEs: CVE-2026-81573, CVE-2026-81574, CVE-2026-81572, CVE-2026-81576, CVE-2026-81575, Summary: The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowing privilege escalation.

EPSS 0.00 CVSS 8.6 CVE-2026-81572 CVE-2026-81573 CVE-2026-81574 CVE-2026-81575 CVE-2026-81576 TRUMPF WIBU-SYSTEMS Wibu-Systems výroba a průmysl FI DE

tg: zranitelnost tp: dodavatelský řetězec tp: průmyslové systémy

· NCSC-FI · TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities · CERT@VDE · TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities

4

SPOJENO PŘES CVE Siemens Mendix SAML

View CSAF Summary Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version. The following versions of Siemens Mendix SAML are affected: Mendix SAML (Mendix 10 compatible) vers:intdot/<4.2.3 (CVE-2026-80465) Mendix SAML (Mendix 11 compatible) vers:intdot/<4.2.3 (CVE-2026-80465) Mendix SAML (Mendix 9.24…

EPSS 0.00 CVSS 8.7 CVE-2026-80465 Siemens výroba a průmysl US IT

tg: zranitelnost tp: identita

· CISA Advisories · Siemens Mendix SAML · CSIRT Itálie (ACN) · Siemens: risolta vulnerabilità in Mendix SAML

Siemens Teamcenter

View CSAF Summary A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following…

EPSS 0.00 CVSS 6.1 CVE-2026-58113 Siemens výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Siemens Teamcenter

Schneider Electric SCADAPack x70 Products

View CSAF Summary Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality. The…

EPSS 0.00 CVSS 6.5 CVE-2026-81861 Schneider Electric výroba a průmysl energetika US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Schneider Electric SCADAPack x70 Products

mySCADA myPRO Manager

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem. The following versions of mySCADA myPRO Manager are affected: mySCADA myPRO Manager <=2.1 (CVE-2026-73807, CVE-2026-82567) CVSS Vendor Equipment Vulnerabilities v3 9.8 mySCADA Technologies mySCADA myPRO Manager Missing Authorization, Missing Authentication for Critical Function Background Critical…

EPSS 0.01 CVSS 9.8 CVE-2026-73807 CVE-2026-82567 mySCADA Technologies výroba a průmysl energetika doprava vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · mySCADA myPRO Manager

1

1

AVEVA Pipeline Integrity Monitor

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513 (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824) CVSS Vendor Equipment Vulnerabilities v3 8.4 AVEVA AVEVA Pipeline Integrity Monitor Use of Hard-coded…

EPSS 0.00 CVSS 8.4 CVE-2026-81821 CVE-2026-81822 CVE-2026-81823 CVE-2026-81824 AVEVA výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · AVEVA Pipeline Integrity Monitor

1

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

OverviewA new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and…

HAProxy média výroba a průmysl US

tg: varování tg: rozbor tp: malware tp: špionáž

· Rapid7 · DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

10

Pyramid Solutions NetStaX EtherNet/IP Stack

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected: EtherNet/IP Adapter DLL Kit (EIPA) EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE) EtherNet/IP Adapter Development Kit (EADK) EtherNet/IP Adapter…

EPSS 0.00 CVSS 9.8 CVE-2026-78012 Pyramid Solutions výroba a průmysl energetika vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Pyramid Solutions NetStaX EtherNet/IP Stack

IXON VPN Client

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VPN Client <1.4.7 (CVE-2026-75925) CVSS Vendor Equipment Vulnerabilities v3 9.6 IXON IXON VPN Client Improper Neutralization of CRLF Sequences ('CRLF Injection') Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy,…

EPSS 0.01 CVSS 9.6 CVE-2026-75925 IXON energetika výroba a průmysl vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · IXON VPN Client

Rockwell Automation ArmorStart LT

View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT <=v2.001 (CVE-2026-19471, CVE-2026-19472) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ArmorStart LT Improper Neutralization of Input During…

EPSS 0.00 CVSS 7.5 CVE-2026-19471 CVE-2026-19472 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation ArmorStart LT

Rockwell Automation ControlFLASH

View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell Automation ControlFLASH are affected: ControlFLASH <=V15.07 (CVE-2026-12663) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation ControlFLASH Missing Authentication for Critical Function Background Critical…

EPSS 0.00 CVSS 7.3 CVE-2026-12663 Rockwell Automation výroba a průmysl energetika vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation ControlFLASH

Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra…

EPSS 0.00 CVSS 8.3 CVE-2026-4827 Schneider Electric energetika vodárenství výroba a průmysl US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

Tycon Systems TPDIN-Monitor-WEB3

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulnerabilities v3 8.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials, Cross-Site…

EPSS 0.00 CVSS 8.8 CVE-2026-77847 CVE-2026-82684 CVE-2026-82712 Tycon Systems výroba a průmysl energetika US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Tycon Systems TPDIN-Monitor-WEB3

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA LocalDiscoveryServer (LDS) Execution with Unnecessary Privileges Background Critical Infrastructure…

CVSS 4.6 CVE-2026-77477 OPC Foundation energetika vodárenství výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · OPCFoundation OPC UA LocalDiscoveryServer (LDS)

Inductive Automation Ignition

View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive Automation Ignition Incorrect Default Permissions Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology Countries/Areas Deployed: Worldwide Company…

EPSS 0.01 CVSS 8.8 CVE-2026-77393 Inductive Automation výroba a průmysl energetika US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Inductive Automation Ignition

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985) CVSS Vendor Equipment Vulnerabilities v3 9.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB2 Missing…

EPSS 0.00 CVSS 9.8 CVE-2026-55985 CVE-2026-61884 Tycon Systems výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Tycon Systems TPDIN-Monitor-WEB2 (Update A)

Rockwell Automation 1756-ENBT Module

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Critical Manufacturing, Food and Agriculture,…

CVSS 7.5 CVE-2025-10478 Rockwell Automation výroba a průmysl doprava vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation 1756-ENBT Module

1

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

In this article Attack chain overviewCampaign scope and targetingMitigation and protection guidanceReferencesLearn more Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of…

zdravotnictví výroba a průmysl veřejná správa školství US

tg: varování tg: rozbor tp: malware

· Microsoft Security Blog · Counterfeit installers to system compromise: Tracking a deceptive software download campaign

6

Rockwell Automation FactoryTalk Activation Manager

View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States…

EPSS 0.00 CVSS 7.8 CVE-2026-16675 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation FactoryTalk Activation Manager

Rockwell Automation Redundancy Module Configuration Tool

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633) Redundancy Module Configuration Tool >=9.00.00|<=10.00.00 (CVE-2026-9634) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation Redundancy Module…

EPSS 0.00 CVSS 7.3 CVE-2026-9633 CVE-2026-9634 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation Redundancy Module Configuration Tool

Rockwell Automation Logix Platform

View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)…

EPSS 0.00 CVSS 7.5 CVE-2026-9637 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation Logix Platform

Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix

View CSAF Summary The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected: ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE…

EPSS 0.03 CVSS 7.5 CVE-2021-42260 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix

Rockwell Automation Historian ME

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background…

EPSS 0.00 CVSS 8.0 CVE-2025-12768 CVE-2026-12661 Rockwell Automation výroba a průmysl zdravotnictví vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation Historian ME

Rockwell Automation RSLinx Classic

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx Classic <=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) CVSS Vendor Equipment Vulnerabilities v3 8.6 Rockwell Automation Rockwell Automation RSLinx Classic Integer Overflow or Wraparound, Integer Underflow (Wrap or Wraparound), Buffer Copy…

EPSS 0.00 CVSS 8.6 CVE-2026-9621 CVE-2026-9622 CVE-2026-9624 CVE-2026-9625 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: DDoS tp: průmyslové systémy

· CISA Advisories · Rockwell Automation RSLinx Classic

3

[Control Systems] National Instruments security advisory (AV26-856)

Serial Number: AV26-856Date: August 28, 2026 As of August 25, 2026, National Instruments is affected by vulnerabilities in the following product: LabVIEW Prior to 23.0.0 Prior to 23.3.10 Prior to 24.3.7 Prior to 25.3.5 Prior to 26.3.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Memory Corruption Vulnerabilities in NI LabVIEW - NI Integer Conversion Vulnerability Resulting in an Out of Bounds Read…

National Instruments výroba a průmysl energetika vodárenství telekomunikace CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] National Instruments security advisory (AV26-856)

SPOJENO PŘES CVE PaperCut NG/MF Critical Zero-Day Exploited in the Wild

Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the time of writing, the vulnerability has not been assigned a CVE identifier, and PaperCut has not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details…

KEV ✓ · ransomware EPSS 1.00 CVE-2023-27350 PaperCut Software PaperCut školství výroba a průmysl US

tg: zneužíváno tg: zranitelnost tp: malware

· Rapid7 · PaperCut NG/MF Critical Zero-Day Exploited in the Wild · BleepingComputer · PaperCut warns of NG, MF flaw exploited in zero-day attacks

CISA Releases Seven Industrial Control Systems Advisories

Classification: Severe, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2018-19518, CVE-2019-11043, CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977, CVE-2018-1285, CVE-2026-18717, CVE-2026-75112, CVE-2026-78037, CVE-2026-78239 (+3 other associated CVEs), Summary: CISA released seven Industrial Control…

CVSS 9.8 Mitsubishi Electric Rockwell Automation výroba a průmysl FI

· NCSC-FI · CISA Releases Seven Industrial Control Systems Advisories

7

Mitsubishi Electric CNC Series (Update A)

View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products. The following versions of Mitsubishi Electric CNC Series (Update A) are affected: Mitsubishi Electric M800VW (BND-2051W000) <=BB (CVE-2025-2399) Mitsubishi Electric M800VS (BND-2052W000) <=BB (CVE-2025-2399) Mitsubishi Electric M80V (BND-2053W000) <=BB (CVE-2025-2399) Mitsubishi Electric M80VW (BND…

EPSS 0.01 CVSS 5.9 CVE-2025-2399 Mitsubishi Electric výroba a průmysl US

· CISA Advisories · Mitsubishi Electric CNC Series (Update A)

Rockwell Automation OTTO Fleet Manager

View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The following versions of Rockwell Automation OTTO Fleet Manager are affected: OTTO Fleet Manager <=V2.36.2 (CVE-2026-75112) CVSS Vendor Equipment Vulnerabilities v3 6.8 Rockwell Automation Rockwell Automation OTTO Fleet Manager Use of Password Hash With Insufficient Computational Effort Background…

EPSS 0.00 CVSS 6.8 CVE-2026-75112 Rockwell Automation výroba a průmysl doprava US

· CISA Advisories · Rockwell Automation OTTO Fleet Manager

All-Line Equipment Company Fuel-Boss

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. The following versions of All-Line Equipment Company Fuel-Boss are affected: Fuel-Boss V1 Standard >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Portal >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Master/Slave >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Backflush Systems >=|<…

KEV ✓ · ransomware EPSS 1.00 CVSS 8.7 CVE-2018-19518 CVE-2019-11043 All-Line Equipment Company výroba a průmysl obrana doprava US

· CISA Advisories · All-Line Equipment Company Fuel-Boss

Applied Systems Engineering ASE2000 V2 Communications Test Set

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications. The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected: ASE2000 >=2.25|<=2.37 (CVE-2018-1285, CVE-2026-18717) CVSS Vendor…

EPSS 0.17 CVSS 9.8 CVE-2018-1285 CVE-2026-18717 Applied Systems Engineering energetika vodárenství výroba a průmysl US

· CISA Advisories · Applied Systems Engineering ASE2000 V2 Communications Test Set

Mitsubishi Electric Multiple FA Products (Update D)

View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product. The following versions of Mitsubishi Electric Multiple FA Products (Update D) are affected: Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32D <=09 (CVE-2025-3511) Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32T <=09 (CVE-2025…

EPSS 0.01 CVSS 7.5 CVE-2025-3511 Mitsubishi Electric výroba a průmysl US

· CISA Advisories · Mitsubishi Electric Multiple FA Products (Update D)

Threat landscape for industrial automation systems. Q2 2026

All threats In Q2 2026, the percentage of ICS computers on which malicious objects were blocked continued to decrease, falling to 19.15%, its lowest level since 2022. Percentage of ICS computers on which malicious objects were blocked, Q3 2023–Q2 2026 Regionally, the percentages ranged from 8.1% in Northern Europe to 27.9% in Africa. Regions ranked by percentage of attacked ICS computers The figures increased in five regions over the quarter, most notably in East Asia (by 2.0 pp) and Africa (by…

Kaspersky výroba a průmysl energetika RU

· Securelist (Kaspersky) · Threat landscape for industrial automation systems. Q2 2026

Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.3, CVEs: CVE-2026-15203, Summary: Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanism

EPSS 0.00 CVSS 9.3 CVE-2026-15203 Danfoss výroba a průmysl energetika FI

· NCSC-FI · Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software

1

PLC na internete: aktuálne riziko aj pre kritickú infraštruktúru

Národné centrum kybernetickej bezpečnosti (NCKB) NBÚ upozorňuje na nebezpečenstvo prevádzkovania programovateľných logických radičov (ďalej ako „PLC“) voľne dostupných z verejného internetu. PLC nie je zariadenie, ktoré má byť priamo dostupné z verejného internetu. Programovateľné logické radiče hrajú kľúčovú úlohu takmer vo všetkých odvetviach priemyslu. Ich vystavenie do verejného internetu môže viesť k ohrozeniu útočníkmi s... The post PLC na internete: aktuálne riziko aj pre kritickú…

energetika vodárenství výroba a průmysl telekomunikace SK

· SK-CERT (NBÚ SR) · PLC na internete: aktuálne riziko aj pre kritickú infraštruktúru

3

Siemens SIMATIC IoT2050 Advanced

View CSAF Summary SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version. The following versions of Siemens SIMATIC…

EPSS 0.01 CVSS 10.0 CVE-2026-58115 Siemens energetika výroba a průmysl doprava US

· CISA Advisories · Siemens SIMATIC IoT2050 Advanced

Ebyte NE2-D11

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation. The following versions of Ebyte NE2-D11 are affected: NE2-D11 Firmware FW-9167-0-11 CVSS Vendor Equipment Vulnerabilities v3 9.8 Ebyte Ebyte NE2-D11 Missing Authentication for Critical Function, Cleartext Transmission of Sensitive Information…

EPSS 0.01 CVSS 9.8 CVE-2026-71187 CVE-2026-73125 CVE-2026-73809 CVE-2026-73839 CVE-2026-75814 CVE-2026-76179 CVE-2026-76940 Ebyte výroba a průmysl energetika US

· CISA Advisories · Ebyte NE2-D11

Murrelektronik: Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches

[VDE-2026-061] An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been…

EPSS 0.00 CVE-2026-8173 Murrelektronik výroba a průmysl DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Murrelektronik: Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches

1

24th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people – roughly two-thirds of the country’s population – as well as 200,000 organizations. The stolen data included identification numbers, license plates, payment amounts, dates and addresses. Attackers reportedly exploited a…

KEV ✓ · ransomware EPSS 0.41 CVSS 10.0 CVE-2026-12569 CVE-2026-19478 CVE-2026-19489 CVE-2026-19490 Snowflake Siemens GitLab Cisco zdravotnictví výroba a průmysl energetika vodárenství IL

· Check Point Research · 24th August – Threat Intelligence Report

1

SPOJENO PŘES CVE CISA Releases One Industrial Control Systems Advisory

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 5.3, CVEs: CVE-2026-27875, Summary: CISA released one Industrial Control Systems (ICS) Advisory. This advisory provides timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-26-232-01 Johnson Controls Simplex Incident Manager

EPSS 0.00 CVSS 5.8 CVE-2026-27875 Johnson Controls výroba a průmysl energetika doprava veřejná správa FI US

· NCSC-FI · CISA Releases One Industrial Control Systems Advisory · CISA Advisories · Johnson Controls Simplex Incident Manager

1

Frequently asked questions about the active threat to Siemens S7 Series PLCs

A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.Key TakeawaysUnattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future disruptive attacks against Siemens S7 Series PLCs.The attackers are leveraging AI to build and refine…

Siemens veřejná správa energetika vodárenství výroba a průmysl US

· Tenable Research · Frequently asked questions about the active threat to Siemens S7 Series PLCs

4

NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.

Siemens energetika výroba a průmysl vodárenství US

· The Record · NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

Defending Against an Active Threat to Siemens S7 Series PLCs

Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. Top Mitigations Inventory all Siemens S7 Series programmable logic…

Siemens výroba a průmysl energetika vodárenství obrana US

· CISA Advisories · Defending Against an Active Threat to Siemens S7 Series PLCs

CISA Releases Two Industrial Control Systems Advisories

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.8, CVEs: CVE-2026-63133, CVE-2026-63134, CVE-2026-55676, CVE-2026-63177, CVE-2026-19670, CVE-2026-19671, CVE-2026-59086, Summary: CISA released two Industrial Control Systems (ICS) Advisories. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-26-230-01 CISA Malcolm ICSA-26-230-02 Siemens Simcenter Nastran

EPSS 0.00 CVSS 8.8 CVE-2026-19670 CVE-2026-19671 CVE-2026-55676 CVE-2026-59086 CVE-2026-63133 CVE-2026-63134 CVE-2026-63177 Siemens výroba a průmysl FI

· NCSC-FI · CISA Releases Two Industrial Control Systems Advisories

3

SPOJENO PŘES CVE Clop created custom web shell for Windchill data theft attacks

A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]

KEV ✓ · ransomware EPSS 0.41 CVE-2026-12569 PTC General Electric Philips výroba a průmysl US

· BleepingComputer · Clop created custom web shell for Windchill data theft attacks · Wiz Research · Cl0p Exploitation of PTC Windchill and FlexPLM Vulnerability (Campaign)

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive…

CVSS 7.0 Microsoft veřejná správa finance zdravotnictví výroba a průmysl US

tg: rozbor tp: ransomware tp: AI tp: špionáž tp: průmyslové systémy

· Rapid7 · New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Siemens Simcenter Nastran

View CSAF Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions. The…

EPSS 0.00 CVSS 7.8 CVE-2026-59086 Siemens výroba a průmysl obrana energetika zdravotnictví US

· CISA Advisories · Siemens Simcenter Nastran

4

Haiwell IoT Cloud HMI Gateway

View CSAF Summary Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected: Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188) CVSS Vendor Equipment Vulnerabilities v3 10 Haiwell Haiwell IoT Cloud HMI Gateway Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors:…

EPSS 0.02 CVSS 10.0 CVE-2026-19188 Haiwell energetika výroba a průmysl vodárenství US

· CISA Advisories · Haiwell IoT Cloud HMI Gateway

Siemens Simcenter Femap

View CSAF Summary Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version. The following versions of Siemens Simcenter Femap are affected: Simcenter…

EPSS 0.00 CVSS 7.8 CVE-2026-59700 CVE-2026-59701 Siemens výroba a průmysl US

· CISA Advisories · Siemens Simcenter Femap

AVEVA Enterprise SCADA

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are affected: Enterprise SCADA 2025 (CVE-2025-7639) Enterprise SCADA >=2024|<=2024_SP1_P01 (CVE-2025-7639) Enterprise SCADA >=2023|<=2023_SP1 (CVE-2025-7639) Enterprise SCADA >=2022|<=2022_SP2_P2 (CVE-2025-7639) Enterprise SCADA <=2021_SP2_P5 (CVE-2025-7639)…

EPSS 0.00 CVSS 7.1 CVE-2025-7639 AVEVA výroba a průmysl energetika US

· CISA Advisories · AVEVA Enterprise SCADA

Siemens Solid Edge

View CSAF Summary Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Solid Edge are affected: Solid Edge SE2025 vers:intdot/<225.0.15 (CVE-2026-50058, CVE-2026…

EPSS 0.00 CVSS 7.8 CVE-2026-50058 CVE-2026-50059 CVE-2026-50060 CVE-2026-50061 CVE-2026-50062 CVE-2026-50063 CVE-2026-50064 Siemens výroba a průmysl US

· CISA Advisories · Siemens Solid Edge