BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
How AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 20m agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 46m agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 52m agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 1h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 1h agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 1h agoCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootThe Hacker News · 1h agoMicrosoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled ThreatsInfosecurity Magazine · 1h agoOver 24,000 exposed server BMCs leak password hash via decades-old flawBleepingComputer · 2h agoNimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysThe Hacker News · 2h agoConfidential Computing on CPU and GPU Systems: How AI Data Centers Protect Data in UseHackRead · 2h agoAxon Is Another License Plate Surveillance CompanySchneier on Security · 3h agoCoca-Cola Reveals Subsidiary Fairlife Suffered Data BreachInfosecurity Magazine · 3h agoFake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor InfectionsHackRead · 3h agoHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 20m agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 46m agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 52m agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 1h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 1h agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 1h agoCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootThe Hacker News · 1h agoMicrosoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled ThreatsInfosecurity Magazine · 1h agoOver 24,000 exposed server BMCs leak password hash via decades-old flawBleepingComputer · 2h agoNimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysThe Hacker News · 2h agoConfidential Computing on CPU and GPU Systems: How AI Data Centers Protect Data in UseHackRead · 2h agoAxon Is Another License Plate Surveillance CompanySchneier on Security · 3h agoCoca-Cola Reveals Subsidiary Fairlife Suffered Data BreachInfosecurity Magazine · 3h agoFake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor InfectionsHackRead · 3h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

1365 results in Vulnerability

VulnerabilityThe Hacker News·11d ago
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing. Google has to ship it in the next major release, Android 18, and by 1 August 2027 at

VulnerabilityThe Hacker News·11d ago
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?

Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from concept to operational deployment at commercial speed. Now the focus shifts to the trusted

VulnerabilityThe Hacker News·12d ago
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token from issuer A carrying a sub that belongs to someone under issuer B logged you in as them. Their password never

VulnerabilityRapid7·12d ago
Sunsetting the Public AttackerKB Platform

What’s changing, where AttackerKB-style analysis will live, and how users can continue finding Rapid7 vulnerability intelligence. On August 18, Rapid7 will sunset the standalone public AttackerKB website as part of a broader effort to unify our vulnerability intelligence, exploit analysis, and research resources. Security practitioners, researchers, vulnerability managers, and current AttackerKB API users will still be able to find Rapid7 vulnerability intelligence through the Rapid7 blog , the recently revamped Rapid7 Vulnerability and Exploit Database , and customer-specific API experiences, where applicable. The public AttackerKB platform is going away, but the intelligence and analysis that security teams rely on are not disappearing. Instead, they’re moving into experiences more closely connected with Rapid7’s broader research and vulnerability intelligence ecosystem. What’s changing The public AttackerKB website will be retired on August 18. AttackerKB-style Rapid7 technical write-ups will continue on the Rapid7 blog. Vulnerability intelligence will remain connected to the Rapid7 Vulnerability and Exploit Database. Open community contributions and the current public AttackerKB API will be retired. Where AttackerKB-style content will live After the AttackerKB site is retired, that particular style of technical write-up will continue to be published through the Rapid7 blog, and will remain connected to the Rapid7 Vulnerability and Exploit Database. This approach brings vulnerability analysis, exploit intelligence, and security research into a more centralized experience for anyone and everyone who accesses the current standalone site. For security practitioners, researchers, and vulnerability managers, the goal is simple: Make it easier to find the information you need without moving between separate platforms. Why we’re retiring community contributions We’re also retiring the open community contribution model of AttackerKB. This decision enables Rapid7 to maintain tighter control over the quality and accuracy of the intelligence we publish. By moving to a more curated model, we can ensure users receive high-fidelity, verified vulnerability intelligence backed by our expert research teams. The change helps protect and fortify the integrity of the intelligence associated with Rapid7, by reducing the risk of inaccurate submissions (especially hastily AI-generated ones), and attempts to manipulate vulnerability information. Maintaining trust in security data is what matters here, and this next step means we can continue delivering intelligence practitioners can use with confidence. What AttackerKB API users should know The current public AttackerKB API will be retired alongside the public platform and community features. Going forward, access to this vulnerability intelligence through APIs will be restructured as a dedicated capability for Rapid7 customers. If your organization currently depends on the public AttackerKB API, Rapid7 will share cu

VulnerabilityThe Hacker News·12d ago
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

ClickLock Stealer, a new macOS infostealer, answers a victim's refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, installs two LaunchAgents and quietly exits. At the next login, Finder, the Dock, Spotlight, Terminal, Activity Monitor, and

VulnerabilityCISA·12d ago
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-06.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. /strong /p p The following versions of Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix are affected: /p ul li CompactLogix 5370 lt;=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li Compact GuardLogix 5370 lt;=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li ControlLogix 5570 lt;=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li GuardLogix 5570 lt;=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li CompactLogix 5380 lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li CompactLogix 5380 lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li Compact GuardLogix 5380 lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li Compact GuardLogix 5380 lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li CompactLogix 5480 lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li CompactLogix 5480 lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li ControlLogix 5580 lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li ControlLogix 5580 lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li GuardLogix 5580 lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li GuardLogix 5580 lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li CompactLogix 5380 Recovery Image lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li Compact GuardLogix 5380 Recovery Image lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li CompactLogix 5480 Recovery Image lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li ControlLogix 5580 Recovery Image lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li GuardLogix 5580 Recovery Image lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 8.6 /td td Rockwell Automation /td td Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix /td td Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" hre

VulnerabilityCISA·12d ago
Rockwell Automation Flex 5000 Adapter

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-08.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product. /strong /p p The following versions of Rockwell Automation Flex 5000 Adapter are affected: /p ul li Flex 5000 Adapter 6.011 (CVE-2026-12659) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation Flex 5000 Adapter /td td Double Free /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing, Information Technology /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-12659 /a /h3 div class="csaf-accordion-content" p A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-12659" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation Flex 5000 Adapter /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation Flex 5000 Adapter: 6.011 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Rockwell Automation recommends users to upgrade to the following: Flex 5000 Adapter version 6.012. /p p strong Mitigation /strong br Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). br a href="https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight" https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight /a /p p strong Mitigation /strong br For more information, see Rockwell Automation Security Advisory SD1789 (https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1789.ht

VulnerabilityCISA·12d ago
Siemens SICAM 8

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-05.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions. /strong /p p The following versions of Siemens SICAM 8 are affected: /p ul li CPCI85 Central Processing/Communication vers:intdot/ lt;26.20 (CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801) /li li SICORE Base system vers:intdot/ lt;26.20.0 (CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.2 /td td Siemens /td td Siemens SICAM 8 /td td Active Debug Code, Initialization of a Resource with an Insecure Default, Unverified Password Change /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing, Energy /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-54798 /a /h3 div class="csaf-accordion-content" p The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-54798" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens SICAM 8 /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br CPCI85 Central Processing/Communication lt; V26.20, SICORE Base system lt; V26.20.0 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Update to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/ /p p strong Vendor fix /strong br Update to V26.20.0 or later version The firmware SICORE V26.20.0 is presen

VulnerabilityCISA·12d ago
SALTO ProAccess Space

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-07.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected. /strong /p p The following versions of SALTO ProAccess Space are affected: /p ul li ProAccess Space lt;6.13 (CVE-2026-11889) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 6.5 /td td SALTO /td td SALTO ProAccess Space /td td Authorization Bypass Through User-Controlled Key /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Commercial Facilities, Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Spain /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-11889 /a /h3 div class="csaf-accordion-content" p SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-11889" View CVE Details /a /p hr h4 Affected Products /h4 h5 SALTO ProAccess Space /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br SALTO /div div class="ics-version" strong Product Version: /strong br SALTO ProAccess Space: lt;6.13 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br Users of SALTO ProAccess using the tenancy feature should upgrade to version 6.13. /p p strong Vendor fix /strong br To further enhance security after applying the update: 1. Operate ProAccess Space on a protected internal network and avoid exposing it directly to the Internet. 2. Restrict operator-level accounts to the minimum required and apply least-privilege principles. 3. If feasible, disable the partitioning feature and operate under a single partition. 4. When strong tenant separation is required, consider running separate Space instances (isolated environments) rather than relying solely on logical partitioning. /p /div p strong Relevant CWE: /strong a href=

VulnerabilityCISA·12d ago
Rockwell Automation FactoryTalk DataMosaix

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-09.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server. /strong /p p The following versions of Rockwell Automation FactoryTalk DataMosaix are affected: /p ul li DataMosaix Private Cloud lt;=8.02 (CVE-2026-9292) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 6.1 /td td Rockwell Automation /td td Rockwell Automation FactoryTalk DataMosaix /td td Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing, Information Technology /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-9292 /a /h3 div class="csaf-accordion-content" p A Stored Cross-Site Scripting security issue exists within FactoryTalk DataMosaix Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-9292" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation FactoryTalk DataMosaix /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation DataMosaix Private Cloud: lt;=8.02 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Rockwell Automation recommends users to upgrade to the following: DataMosaix Private Cloud versions 8.03 or later. /p p strong Mitigation /strong br Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). br a href="https://s

VulnerabilityCISA·12d ago
NASA Core Flight System (cFS) Health & Safety (HS) Application

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-03.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. /strong /p p The following versions of NASA Core Flight System (cFS) Health amp; Safety (HS) Application are affected: /p ul li Core Flight System (cFS) Health amp; Safety (HS) Application /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td NASA /td td NASA Core Flight System (cFS) Health amp; Safety (HS) Application /td td NULL Pointer Dereference /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Transportation Systems /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-15352 /a /h3 div class="csaf-accordion-content" p A vulnerability exists in the Health amp; Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-15352" View CVE Details /a /p hr h4 Affected Products /h4 h5 NASA Core Flight System (cFS) Health amp; Safety (HS) Application /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br NASA /div div class="ics-version" strong Product Version: /strong br NASA Core Flight System (cFS) Health amp; Safety (HS) Application: lt;v7.0.1 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br NASA recommends users update to v7.0.1 (https://github.com/nasa/HS/releases/tag/v7.0.1) br a href="https://github.com/nasa/HS/releases/tag/v7.0.1" https://github.com/nasa/HS/releases/tag/v7.0.1 /a /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/476.html" CWE-476 NULL Pointer Dereference /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS Version /th th role="columnheader" Base Score /th th role="columnheader" Base Severity /th th role="columnheader" Vector String /th /tr /thead tbody tr td 3.1 /td td 7.5 /td td HIGH /td td a hre