Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender as part of a limited-access pilot
Security & IT News
LiveReal-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.
Learn how Fig adds testing, deployment, and continuous verification to SecOps, helping security teams keep detections reliable as infrastructure evolves. daily.
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE
A hacker took names, phone numbers, and physical addresses of millions of customers who used AI music generator Suno.
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway
Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. [...]
Russian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude models
Not everything our honeypots detect is an attack. Sometimes it is just odd traffic , and this is one example: Our First Seen list currently includes http://detectportal.firefox.co m/success.txt as one of the new URLs detected by our honeypots. The hostname detectportal kind of gives away what is happening here. If you have ever tried to connect to a public WiFi network, you probably ran into some type of captive portal . A splash screen that will ask you to acknowledge some kind of user agreement or require you to log in. Of course, each implementation looks a bit different, and browsers and operating systems attempt to detect these captive portals. Typically, the operating system will automatically direct you to the correct portal page. It used to be easier to deal with captive portals. Back in the old days (not necessarily good old days ), users often had a non-TLS page configured as their homepage. The captive portal was able to intercept this connection and direct the user to the captive portal's login page. These days, however, most websites use TLS, and browsers default to TLS for many sites and refuse to switch to a non-TLS site. This made using WiFi networks a lot safer, but it gets in the way of directing users to a captive portal. In response, operating systems and browsers implemented features to detect captive portals. The system will attempt to pull up a specific http URL to detect if it receives a redirect response. If so, it will open the redirect URL in a browser. You will see these URLs as systems join your network, or if the browser is started. The URL does provide some intelligence as to what operating system or browser is being used. Here is a quick summary of what URLs different operating systems use: Windows: http://www.msftconnecttest.com/connecttest.txt . This is part of the Windows Network Connectivity Status Indicator, which was introduced in Windows 8. Windows 10 and later will attempt to access the URL and check for a valid response. The response should be Microsoft Connect Test . In addition, it will do a DNS lookup for dns.msftncsi.com. [1] Apple: Recent versions of MacOS and iOS use http://captive.apple.com/hotspot-detect.html as a test. The expected response is Success . If the system can not connect, Apple's Captive Network Assistant starts to assist the user in logging in. Android: http://connectivitycheck.android.com/generate_204. The result page is empty, and uses a status code of 204 (No Content). Chrome: http://www.gstatic.com/generate_204. Slightly different URL than Chrome, but works the same way expecting a 204 No Content response. Chromium implements the same system with http://clients3.google.com/generate_204 [3] Firefox: http://detectportal.firefox.com/canonical.html. This page returns a 200 status code. The body of the page includes a META tag to redirect users to a page explaining how Firefox deals with captive portals (I like this.. as an analyst, it is neat to have the page explain what it d
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. Also patched
Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented
Fake FBI agents are using deepfake videos, spoofed IC3 websites and false recovery claims to steal money and personal information from people who were scammed before, the FBI warns.
p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-05.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. /strong /p p The following versions of Rockwell Automation ThinManager are affected: /p ul li ThinManager gt;=13.0.0| lt;13.0.7, gt;=13.1.0| lt;13.1.5, gt;=13.2.0| lt;13.2.4, gt;=14.0.0| lt;14.0.2 /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 8.1 /td td Rockwell Automation /td td Rockwell Automation ThinManager /td td Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-11917 /a /h3 div class= csaf-accordion-content p A path traversal security issue exists within Rockwell Automation ThinManager software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-11917 View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation ThinManager /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Rockwell Automation /div div class= ics-version strong Product Version: /strong br Rockwell Automation ThinManager: gt;=13.0.0| lt;13.0.7, Rockwell Automation ThinManager: gt;=13.1.0| lt;13.1.5, Rockwell Automation ThinManager: gt;=13.2.0| lt;13.2.4, Rockwell Automation ThinManager: gt;=14.0.0| lt;14.0.2 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Mitigation /strong br Users using the affected software, should upgrade to one of the corrected versions as follows: /p p strong Vendor fix /strong br ThinManager Versions 13.0.0 - 13.0.7 -- gt; 13.0.8 /p p strong Vendor fix /strong br ThinManager Versions 13.1.0 - 13.1.5 -- gt; 13.1.6 /p p strong Vendor fix /strong br ThinManager Versions 13.2.0 - 13.2.4 -- gt; 13.2.5 /p p strong Vend
p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-08.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. /strong /p p The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected: /p ul li 1718/ 1719 Ex I/O 3.011 nbsp; /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation 1718-AENTR/1719-AENTR /td td Allocation of Resources Without Limits or Throttling /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-9140 /a /h3 div class= csaf-accordion-content p A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-9140 View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation 1718-AENTR/1719-AENTR /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Rockwell Automation /div div class= ics-version strong Product Version: /strong br Rockwell Automation 1718/ 1719 Ex I/O: 3.011 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Vendor fix /strong br Rockwell Automation recommends users to upgrade to 1718/ 1719 Ex I/O version 3.012 or later. /p p strong Mitigation /strong br Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). br a href= https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight /a /p p strong Mitigation /strong br For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html. br a href= https://www.rockwellautomation.com/en-
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-03.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version. /strong /p p The following versions of Siemens Opcenter X are affected: /p ul li Opcenter X vers:intdot/ lt;2604 /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 10 /td td Siemens /td td Siemens Opcenter X /td td Improper Verification of Cryptographic Signature /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-56451 /a /h3 div class="csaf-accordion-content" p Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-56451" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens Opcenter X /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br Opcenter X lt; V2604 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Update to V2604 or later version br a href="https://support.sw.siemens.com/product/206159703/" https://support.sw.siemens.com/product/206159703/ /a /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/347.html" CWE-347 Improper Verification of Cryptographic Signature /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS Version /th th role="columnheader" Base Score /th th role="columnheader" Base Severity /th th role="columnheader" Vector String /th /tr /thead tbody tr td 3.1 /td td 10 /td td CRITICAL /td td a
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-07.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations. /strong /p p The following versions of Rockwell Automation FactoryTalk Services Platform are affected: /p ul li FactoryTalk Directory (FTSP) 6.60 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.8 /td td Rockwell Automation /td td Rockwell Automation FactoryTalk Services Platform /td td Weak Authentication /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-10714 /a /h3 div class="csaf-accordion-content" p A security issue exists within FactoryTalk Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and craft forged tokens. This could allow an authenticated low-privilege user to impersonate any authorized user on the FTSP server, resulting in unauthorized access to system configuration and the ability to grant permissions to other systems protected by FTSP. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-10714" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation FactoryTalk Services Platform /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation FactoryTalk Directory (FTSP): 6.60 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br Users using FactoryTalk Services Platform v6.60 should apply either the individual patch (RAID 1158263) or the February 2026 Patch Roll-up, or later update. /p p strong Mitigation /strong br Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell's security best practices. br a href="https://support.rockwellautomation.com/app/answers/answer_view/a_id
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-06.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. /strong /p p The following versions of Siemens CADRA are affected: /p ul li CADRA vers:intdot/ lt;2511, vers:all/* nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 9.8 /td td Siemens /td td Siemens CADRA /td td Improper Input Validation, Incorrect Bitwise Shift of Integer, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Access of Resource Using Incompatible Type ('Type Confusion') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Chemical, Commercial Facilities, Communications, Energy /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2005-2096 /a /h3 div class="csaf-accordion-content" p zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file. /p p a href="https://www.cve.org/CVERecord?id=CVE-2005-2096" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens CADRA /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br CADRA lt; V2511 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Update to V2511 or later version /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/20.html" CWE-20 Improper Input Validation /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS Version /th th role="columnheader" Base Score /th th role="columnheader" Base Severity /th th role="columnheader" Vector String /th /tr /thead tbo
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-10.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. /strong /p p The following versions of Rockwell Automation Studio 5000 Logix Designer are affected: /p ul li Studio 5000 Logix Designer V36.00 (CVE-2026-9108) /li li Studio 5000 Logix Designer V35.00 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) /li li Studio 5000 Logix Designer V35.01 (CVE-2026-9108) /li li Studio 5000 Logix Designer gt;=V34.00| lt;=V34.03 (CVE-2026-9108) /li li Studio 5000 Logix Designer gt;=V33.00| lt;=V33.03 (CVE-2026-9108) /li li Studio 5000 Logix Designer gt;=V32.00| lt;=V32.04 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) /li li Studio 5000 Logix Designer V34.00 (CVE-2026-9127) /li li Studio 5000 Logix Designer V34.01 (CVE-2026-9127) /li li Studio 5000 Logix Designer V33.00 (CVE-2026-9127) /li li Studio 5000 Logix Designer V33.02 (CVE-2026-9127) /li li Studio 5000 Logix Designer gt;=V34.00| lt;=V34.02 (CVE-2026-9128) /li li Studio 5000 Logix Designer gt;=V33.00| lt;=V33.02 (CVE-2026-9128) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation Studio 5000 Logix Designer /td td Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Incorrect Authorization, Unquoted Search Path or Element /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-9108 /a /h3 div class="csaf-accordion-content" p A path traversal security issue exists within Studio 5000 Logix Designer due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-9108" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation Stud
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-09.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. /strong /p p The following versions of Rockwell Automation 1734 POINT I/O are affected: /p ul li 1734 POINT I/O 3.023 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation 1734 POINT I/O /td td Allocation of Resources Without Limits or Throttling /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-10573 /a /h3 div class="csaf-accordion-content" p A denial-of-service security issue exists in 1734 POINT I/O module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-10573" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation 1734 POINT I/O /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation 1734 POINT I/O: 3.023 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br Rockwell Automation recommends users are to migrate to 5034-OB8. /p p strong Mitigation /strong br Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). br a href="https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight" https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight /a /p p strong Mitigation /strong br For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html. br a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html" https://www.r
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-02.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/ /strong /p p The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected: /p ul li RUGGEDCOM APE1808 vers:all/* nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.2 /td td Siemens /td td Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW /td td Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Missing Authorization, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-0266 /a /h3 div class="csaf-accordion-content" p A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-0266" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Contact customer support to receive patch and update information /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/79.html" CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') /a /p hr h4 Metric
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-05.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. /strong /p p The following versions of Siemens IAM Client are affected: /p ul li COMOS V10.4.5 vers:intdot/ lt;10.4.5.0.2 nbsp; /li li COMOS V10.6 vers:intdot/ lt;10.6.1 nbsp; /li li Designcenter NX vers:intdot/ lt;2512.7000 nbsp; /li li Simcenter 3D vers:intdot/ lt;2512.7000 nbsp; /li li Simcenter Femap V2506 vers:intdot/ lt;2506.0003 nbsp; /li li Simcenter Femap V2512 vers:intdot/ lt;2512.0002 nbsp; /li li Simcenter Nastran vers:intdot/ lt;2606 nbsp; /li li Simcenter STAR-CCM+ vers:intdot/ lt;2606 nbsp; /li li Solid Edge SE2025 vers:intdot/ lt;225.0.13.3 nbsp; /li li Solid Edge SE2026 vers:intdot/ lt;226.0.04.003 nbsp; /li li Teamcenter Visualization V2412 vers:intdot/ lt;2412.0012 nbsp; /li li Teamcenter Visualization V2506 vers:intdot/ lt;2506.0009 nbsp; /li li Teamcenter Visualization V2512 vers:intdot/ lt;2512.2605 nbsp; /li li Tecnomatix Plant Simulation V2404 vers:intdot/ lt;2404.0022 nbsp; /li li Tecnomatix Plant Simulation V2504 vers:intdot/ lt;2504.0010 nbsp; /li li Tecnomatix Process Simulate vers:intdot/ lt;2606 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 6.7 /td td Siemens /td td Siemens IAM Client /td td Untrusted Search Path /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Chemical, Critical Manufacturing, Energy /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2025-40945 /a /h3 div class="csaf-accordion-content" p Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access. /p p a href="https://www.cve.org/CVERecord?id=CVE-2025-40945" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens IAM Client /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br COMOS V10.4.5 lt; V1