Siemens Desigo CC
OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for...
Active vulnerabilities, advisories, and threat intelligence — filtered for IT practitioners.
OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for...
Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibili...
Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor application server are a...
Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions of Rockwell Automation Studio 5000...
Update July 16, 2026 : CISA has updated this Alert to reflect the addition of CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) Catalog on July 16, 2026. CISA is aware of active exploitation of vulnerabiliti...
A critical stack-based buffer overflow in Ivanti Connect Secure VPN was exploited as a zero-day by UNC5221 (China-nexus) to deploy TRAILBLAZE dropper and BRUSHFIRE passive backdoor on edge devices globally.
Five vulnerabilities in the Kubernetes ingress-nginx controller, collectively dubbed IngressNightmare, allow unauthenticated attackers with access to the admission webhook to achieve cluster-level code execution.
A trivial header injection in Next.js allows attackers to skip middleware execution entirely, bypassing authentication, authorization, and security checks on any route protected only by Next.js middleware.
A deserialization vulnerability in Veeam Backup & Replication allows any authenticated domain user to execute arbitrary code on the backup server, potentially destroying or encrypting backups before a ransomware attack.
Fortinet's critical authentication bypass in FortiOS and FortiProxy management interfaces is being actively exploited at scale, with attackers creating hidden super-admin accounts and pivoting to internal networks.