US, UK Agencies Detail Iranian Malware Campaign Targeting Dissidents
A new joint advisory from multiple law enforcement agencies this week warned of an Iranian cyber campaign targeting dissidents and journalists in the U.S., UK, and elsewhere.
Architecting a secure landing zone in the AWS European Sovereign Cloud
The AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within the European Union (EU). It provides the same services, features, and APIs as AWS commercial Regions, but runs as a distinct AWS partition (aws-eusc), with its own control plane, AWS Identity and […]
The Apple Security Update Review for September 2026
Welcome back to our monthly look at Apple security patches. This release shows Apple is not immune to the new normal of AI-assisted vulnerability discovery as they release patches for 273 total CVEs.For the September 2026 release, Apple released 273 unique CVEs across macOS 27 (Golden Gate), macOS Sequoia 15.8, macOS Tahoe 26.7, iOS / iPadOS 27, visionOS 27, watchOS 27, tvOS 27, iOS / iPadOS 26.7, Safari 27, and Xcode 27. This patch release actually happened a couple of days ago, but since Apple doesn’t provide CVSS scores or other severity information, it takes a couple of days to understand the full severity. Even with the additional time, there are many CVEs without a severity score. However, looking at the one that do have severity assigned by NVD or CISA-ADP, there are a few that truly stand out, including one under active exploit.CVE-2026-65400 — Screen Sharing Server (9.8 CRITICAL, ⚠ CISA KEV). This bug is confirmed by CISA to be actively exploited. A network attacker can authenticate to Screen Sharing without valid credentials, without user interaction. This component was first patched on August 6 and relisted in v27 as macOS 27/Tahoe 26.7 now carries the fix.CVE-2026-65414 — Bluetooth (9.8 CRITICAL). This is the highest-scored non-exploited bug in the release. It’s remote, network-vector arbitrary code execution with no privileges or interaction, and CISA tagged it "automatable: yes, technical impact: total." It spans all eight OS platforms, which is the broadest-reach critical vulnerability in the release and the most likely candidate to become a KEV entry.CVE-2026-65346 — ImageIO (8.8 HIGH). The bug sits at the top of the HIGH tier and is the most dangerous remote content bug: processing a malicious image leads to arbitrary code execution. ImageIO is the canonical zero-/one-click surface (images auto-rendered in Messages, previews), so it carries high real-world weaponization potential.Two honorable mentions that matter because of a data caveat: CVE-2026-84607 (AVEVideoEncoder) — a sandbox-to-kernel arbitrary-code-execution bug — and CVE-2026-43790 (Kernel) — remote kernel memory corruption — are arguably more severe by impact than #3, but NVD hasn't scored either yet (both TBD), so they don't rank on the current evidence. Also worth noting: CVE-2026-43692 (CUPS) remote code execution and CVE-2026-84568 (autofs) root RCE both sit at the top of the HIGH band.Here’s the full table of Apple patches and the products they affect: Apple Security Updates — September 14, 2026 (v27) 273Total CVEs 134Scored 139TBD 2CRITICAL 46HIGH 84MEDIUM 2LOW CVSS is the NVD primary score where available, otherwise CISA-ADP secondary; TBD = NVD has not scored it yet (most v27 CVEs are still under analysis). ⚠ KEV marks CVEs in CISA's Known Exploited Vulnerabilities catalog. Apple security release — September 14, 2026 (version 27), 273 CVEs. CVSS/Severity from NVD (National Vulnerability Database) as of Sept 16, 2026. CVE IDs link to NVD. "Yes/No" indicates whether each update is affected. CVE IDComponentImpactCVSSSeverity iOS / iPadOS 27 iOS / iPadOS 26.7 macOS 27 (Golden Gate) macOS Tahoe 26.7 macOS Sequoia 15.8 tvOS 27 watchOS 27 visionOS 27 Safari 27 Xcode 27 CVE-2026-65400 Screen Sharing Server An attacker on the network may be able to authenticate to Screen Sharing without valid credentials 9.8⚠ KEV CRITICAL NoNoYesYesNoNoNoNoNoNo CVE-2026-65414 Bluetooth A remote attacker may be able to cause unexpected app termination or arbitrary code execution 9.8CRITICAL YesYesYesYesYesYesYesYesNoNo CVE-2026-43692 CUPS A remote user may cause an unexpected app termination or arbitrary code execution 8.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-65346 ImageIO Processing an image may lead to arbitrary code execution 8.8HIGH NoNoNoNoYesYesYesYesNoNo CVE-2026-43686 Kernel Connecting to a malicious NFS server may lead to kernel memory corruption 8.8HIGH YesYesYesYesYesYesYesYesNoNo CVE-2026-65374 WebDAV Connecting to a malicious WebDAV server may result in code execution 8.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-43715 WebKit Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoYesNoNoNoNoNoNoNoNo CVE-2026-43794 WebKit Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoNoNoNoNoYesYesYesNoNo CVE-2026-65390 WebRTC Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoNoNoNoNoYesYesYesNoNo CVE-2026-65391 WebRTC Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoNoNoNoNoYesYesYesNoNo CVE-2026-43760 Screen Sharing Server An app may be able to access user-sensitive data 8.6HIGH NoNoNoYesNoNoNoNoNoNo CVE-2026-84581 HFS Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory 8.4HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84535 Automator An app may be able to break out of its sandbox 8.2HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84516 CUPS Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory 8.1HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-65415 Kernel A local user may be able to cause unexpected system termination or read kernel memory 8.1HIGH YesNoYesNoNoYesYesYesNoNo CVE-2026-84568 autofs An attacker with control of a network directory server may be able to execute arbitrary code with root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84607 AVEVideoEncoder A sandboxed app may be able to execute arbitrary code with kernel privileges 7.8HIGH YesYesYesYesYesYesYesYesNoNo CVE-2026-84631 Bluetooth An app may be able to gain root privileges 7.8HIGH NoNoYesNoNoNoNoNoNoNo CVE-2026-43786 CoreServices An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84575 CoreUI Processing a maliciously crafted file may lead to unexpected app termination 7.8HIGH YesNoYesYesYesYesYesYesNoNo CVE-2026-43691 CUPS An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-43698 CUPS An app may be able to gain root privileges 7.8HIGH NoNoYesYesNoNoNoNoNoNo CVE-2026-84505 Directory Utility An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-65362 Disk Images An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-64758 ImageIO Processing a maliciously crafted file may lead to unexpected app termination 7.8HIGH NoYesNoNoYesNoNoNoNoNo CVE-2026-43684 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory 7.8HIGH NoYesYesNoYesNoNoNoNoNo CVE-2026-43689 Kernel A malicious app may be able to gain root privileges 7.8HIGH YesYesYesNoNoNoNoYesNoNo CVE-2026-86917 Kernel An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-64712 odproxyd An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84515 SMB Connecting to a malicious SMB server may lead to kernel memory corruption 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84506 udf An app may be able to execute arbitrary code with kernel privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-64761 Accessibility An app may be able to identify what other apps a user has installed 7.5HIGH YesNoNoNoNoNoNoNoNoNo CVE-2026-86895 CloudKit A local app may be able to read a persistent account identifier 7.5HIGH YesNoNoNoNoYesYesYesNoNo CVE-2026-84563 CUPS An app may be able to cause unexpected system termination 7.5HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84606 iCloud An app may be able to identify a user across reinstalls 7.5HIGH YesNoYesNoNoNoNoYesNoNo CVE-2026-43661 ImageIO Processing a maliciously crafted image may corrupt process memory 7.5HIGH NoYesNoNoNoNoNoNoNoNo CVE-2026-28969 IOKit An app may be able to cause unexpected system termination 7.5HIGH YesNoYesYesYesYesYesYesNoNo CVE-2026-65343 Kernel A remote attacker may be able to cause unexpected system termination 7.5HIGH NoNoNoNoNoYesYesYesNoNo CVE-2026-65364 Kernel A remote attacker may be able to cause unexpected system termination 7.5HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-86894 libxpc An app may be able to break out of its sandbox 7.5HIGH NoNoYesNoNoNoNoNoNoNo CVE-2026-84543 SMB Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory 7.5HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84553 smbx A remote attacker may be able to cause a denial-of-service 7.5HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-28930 Spotlight An app may be able to access protected user data 7.5HIGH NoNoNoNoYesNoNoNoNoNo CVE-2026-86904 Watch App An app may be able to track users across apps and websites without permission 7.5HIGH YesYesNoNoNoNoYesNoNoNo CVE-2026-64752 CoreMedia Processing a maliciously crafted image may lead to arbitrary code execution 7.3HIGH YesNoYesNoNoNoNoYesNoNo CVE-2026-84611 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption 7.3HIGH YesYesYesYesYesYesYesYesNoNo CVE-2026-84632 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption 7.3HIGH YesYesYesYesYesYesYesYesNoNo CVE-2026-64736 IOMobileFrameBuffer An app may be able to cause unexpected system termination or corrupt kernel memory 7.1HIGH NoNoNoNoYesYesYesYesNoNo CVE-2026-65349 Kernel An app may be able to cause unexpected system termination or read kernel memory 6.6MEDIUM NoNoNoNoYesYesYesYesNoNo CVE-2026-84537 SMB An app may be able to cause unexpected system termination or corrupt kernel memory 6.6MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-43788 Spotlight Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents 6.6MEDIUM NoNoYesNoNoNoNoNoNoNo CVE-2026-86882 Accelerate Framework Processing a maliciously crafted image may lead to unexpected process termination 6.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84519 AppleDouble Mounting a disk image with maliciously crafted files may lead to unexpected system termination 6.5MEDIUM YesYesYesYesYesNoNoNoNoNo CVE-2026-86879 Baseband A remote attacker may be able to cause a denial-of-service 6.5MEDIUM YesNoNoNoNoNoNoNoNoNo CVE-2026-86885 Baseband An attacker in radio range may be able to cause unexpected system termination 6.5MEDIUM YesNoNoNoNoNoNoNoNoNo CVE-2026-65412 CoreText Processing web content may lead to a denial-of-service 6.5MEDIUM YesYesYesYesYesNoYesYesNoNo CVE-2026-84596 CoreText Processing a maliciously crafted font may result in the disclosure of process memory 6.5MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2026-84597 FontParser Processing a maliciously crafted font may result in the disclosure of process memory 6.5MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2022-3437 Heimdal A user in a privileged network position may be able to leak sensitive user information 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-28934 HFS Mounting a malicious disk image may cause unexpected system termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-65347 ImageIO Processing an image may lead to a denial-of-service 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-65395 ImageIO Processing a maliciously crafted image may result in memory corruption 6.5MEDIUM YesYesYesYesYesYesNoYesNoNo CVE-2026-43687 Kernel Connecting to a malicious NFS server may disclose kernel memory 6.5MEDIUM YesYesYesYesNoYesYesYesNoNo CVE-2026-65330 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory 6.5MEDIUM NoNoNoNoYesYesYesYesNoNo CVE-2026-84538 Kernel A remote attacker may be able to cause a denial-of-service 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84588 Kernel Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory 6.5MEDIUM NoNoYesNoNoNoNoNoNoNo CVE-2026-84487 SceneKit Processing a maliciously crafted file may result in disclosure of process memory 6.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-43719 SMB Mounting a maliciously crafted SMB network share may lead to system termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-65365 SMB Connecting to a malicious SMB share may disclose kernel memory 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84536 SMB Connecting to a malicious SMB server may lead to unexpected system termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-43677 WebDAV Connecting to a malicious WebDAV server may lead to unexpected app termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-64715 WebKit Processing maliciously crafted web content may lead to an unexpected process crash 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-64753 WebKit Processing maliciously crafted web content may disclose sensitive user information 6.5MEDIUM YesNoYesNoNoYesYesYesYesNo CVE-2026-64787 WebKit Processing maliciously crafted web content may lead to an unexpected process termination 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-64778 WebKit History Visiting a maliciously crafted website may leak sensitive data 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-84560 Bluetooth An app may gain unauthorized access to Bluetooth 6.1MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2026-84619 Kernel An app may be able to cause unexpected system termination or write kernel memory 6.1MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84554 CUPS An attacker in a privileged network position may be able to cause a denial-of-service 5.9MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-43664 Accessibility An app may be able to access sensitive user data 5.5MEDIUM YesYesYesYesYesYesYesNoNoNo CVE-2026-65404 Accounts A malicious application may be able to bypass Privacy preferences 5.5MEDIUM YesNoYesNoNoNoNoNoNoNo CVE-2026-84523 APFS An app may be able to cause unexpected system termination or write kernel memory 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84586 Apple Account A malicious application may be able to leak sensitive user information 5.5MEDIUM NoNoYesNoNoNoYesNoNoNo CVE-2026-65407 AppleAVD An app may be able to cause unexpected system termination 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84593 AppleKeyStore An app may be able to cause unexpected system termination 5.5MEDIUM YesNoNoNoNoNoNoNoNoNo CVE-2026-43763 ATS An app may be able to read files outside of its sandbox 5.5MEDIUM NoNoNoYesYesNoNoNoNoNo CVE-2026-86905 Authentication Services An app may be able to delete credentials stored in Keychain 5.5MEDIUM YesNoYesNoNoNoNoYesNoNo CVE-2026-43737 CoreMotion An app may be able to access motion data from headphones without user consent 5.5MEDIUM YesYesYesYesYesYesYesNoNoNo CVE-2026-43738 CoreUI Processing a maliciously crafted asset catalog may result in disclosure of process memory 5.5MEDIUM YesNoYesNoNoNoNoNoNoNo CVE-2026-84489 CoreUI An app may be able to cause a denial of service 5.5MEDIUM YesNoYesNoNoNoNoNoNoNo CVE-2026-84534 file_cmds Extracting a maliciously crafted archive may allow an attacker to write arbitrary files 5.5MEDIUM YesYesYesYesYesNoNoYesNoNo CVE-2026-65409 Foundation An app may be able to cause a denial of service 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-64756 Image Capture An app may be able to access user-sensitive data 5.5MEDIUM YesNoYesYesYesNoNoNoNoNo CVE-2026-64760 IOSurfaceAccelerator An app may be able to leak sensitive kernel state 5.5MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2026-65401 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM NoNoYesYesNoNoNoNoNoNo CVE-2026-65402 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-65405 Kernel An app may be able to determine kernel memory layout 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84517 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84521 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM YesYesYesYesYesNoNoYesNoNo CVE-2026-86903 Kernel An app may be able to disclose kernel memory 5.5MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2026-86883 Managed Configuration An app may be able to access sensitive user data 5.5MEDIUM YesNoNoNoNoNoNoYesNoNo CVE-2026-43741 Messages An app may be able to access protected user data 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84491 Photos Storage An app may be able to access sensitive user data 5.5MEDIUM YesYesYesNoNoYesYesYesNoNo CVE-2026-84576 QuartzCore An app may be able to access sensitive user data 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84555 Sandbox An app may be able to access sensitive user data 5.5MEDIUM NoNoYesNoYesNoNoNoNoNo CVE-2026-65413 SceneKit An app may be able to cause a denial of service 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-28937 Terminal An app may be able to access sensitive user data 5.5MEDIUM NoNoYesNoNoNoNoNoNoNo CVE-2026-64718 WebKit Canvas Processing maliciously crafted web content may lead to an unexpected Safari crash 5.5MEDIUM YesYesYesNoNoNoNoYesYesNo CVE-2026-65393 Xcode IDE An app may be able to access user-sensitive data 5.5MEDIUM NoNoYesNoNoNoNoNoNoYes CVE-2026-84617 XPC An app may be able to access sensitive user data 5.5MEDIUM YesYesYesYesYesYesNoNoNoNo CVE-2026-64788 IOGPUFamily Processing maliciously crafted web content may lead to memory corruption 5.4MEDIUM NoNoNoNoNoNoYesYesNoNo CVE-2026-65341 WebKit Processing maliciously crafted web content may lead to memory corruption 5.4MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-34979 CUPS An attacker in a privileged network position may be able to cause a denial-of-service 5.3MEDIUM NoNoYesNoNoNoNoNoNoNo CVE-2026-86876 CoreMedia A sandboxed process may be able to circumvent sandbox restrictions 5.2MEDIUM YesYesYesYesYesNoYesYesNoNo CVE-2026-86889 Security An attacker in a privileged network position may be able to intercept network traffic 4.8MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84492 Graphics An app may be able to cause unexpected system termination 4.7MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84630 Kernel An app may be able to cause unexpected system termination 4.7MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-43690 SMB A local user may be able to read kernel memory 4.7MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84518 Safari A malicious website may be able to determine what apps a user has installed 4.3MEDIUM YesNoYesNoNoNoNoNoYesNo CVE-2026-43795 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-64780 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-64781 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-64784 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65331 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65332 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65333 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65334 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65335 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65336 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65337 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65338 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65340 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65351 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-64782 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 3.1LOW NoNoNoNoNoNoNoYesNoNo CVE-2026-64779 WebKit Storage Processing maliciously crafted web content may lead to an unexpected Safari crash 3.1LOW NoNoNoNoNoNoNoYesNoNo CVE-2026-86910 APFS An application may be able to access restricted files TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-86888 App Store A local app may be able to read a persistent account identifier TBDTBD YesNoYesYesNoYesYesYesNoNo CVE-2026-84587 AppKit An app may be able to access protected user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-20683 Apple Account An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account TBDTBD YesNoYesYesYesNoNoYesNoNo CVE-2026-84601 Apple Intelligence An app may be able to bypass Apple Intelligence security prompts TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-65408 Apple Neural Engine An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-84520 AppleFDEKeyStore A local attacker may be able to cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-65381 AppleMobileFileIntegrity A malicious app may be able to break out of its sandbox TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84522 Archive Utility An app may be able to access sensitive user data TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84584 Archive Utility An app may be able to break out of its sandbox TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-65342 ATS An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84525 ATS An app may be able to access user-sensitive data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65339 Audio An app may be able to leak sensitive user information TBDTBD NoNoNoNoYesYesYesYesNoNo CVE-2026-84583 AuthKit A local app may be able to read a persistent account identifier TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84570 autofs An app may be able to bypass Gatekeeper checks TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65410 AVEVideoEncoder An app may be able to cause unexpected system termination TBDTBD YesYesYesYesNoYesYesYesNoNo CVE-2026-84616 AVEVideoEncoder An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-65406 BackgroundAssets An app may be able to access sensitive user data TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-86878 Camera An app may be able to access sensitive user data TBDTBD YesNoNoNoNoNoNoNoNoNo CVE-2026-84567 cd9660 An app may be able to cause unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-86893 CloudKit An app may be able to read device name TBDTBD YesNoNoNoNoYesYesYesNoNo CVE-2026-65399 copyfile An archive may be able to bypass Gatekeeper TBDTBD YesYesYesYesYesNoYesYesNoNo CVE-2026-86891 Core Bluetooth An app may be able to access Bluetooth device information TBDTBD NoNoYesYesYesNoYesNoNoNo CVE-2026-43683 CoreDrag An app may be able to cause unexpected process termination or disclose process memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-43789 CoreMedia An app may be able to access user-sensitive data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65344 CoreMedia Processing a maliciously crafted video file may lead to unexpected app termination TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-43702 CoreMedia Video Toolbox Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory TBDTBD NoYesNoYesYesNoNoNoNoNo CVE-2026-84624 CoreML A sandboxed app may be able to access restricted files TBDTBD YesYesYesYesYesNoNoYesNoNo CVE-2026-84559 CoreServices A malicious application may be able to access restricted files TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84574 CoreServices An app may be able to bypass Privacy preferences TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84511 CoreUI Processing a maliciously crafted asset catalog may lead to unexpected process termination TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-84571 CoreUI Processing a maliciously crafted image may lead to unexpected app termination TBDTBD YesNoYesNoNoYesYesYesNoNo CVE-2026-64790 CUPS An app may be able to gain elevated privileges TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84540 CUPS An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84541 CUPS An application may be able to access restricted files TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84612 DeviceCheck An app may be able to read persistent device identifiers TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84512 Disk Images Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84550 Disk Images An app may be able to cause unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84552 Disk Images An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-84565 Disk Images Processing a maliciously crafted disk image may lead to unexpected app termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84510 exFAT Mounting a maliciously crafted volume may lead to unexpected system termination TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-86900 exFAT Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-86901 exFAT Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-43785 File Bookmark An app may be able to modify a file it only had permission to read TBDTBD YesNoYesYesYesYesNoYesNoNo CVE-2026-43688 Filters Processing a maliciously crafted file may lead to unexpected app termination TBDTBD YesNoYesNoNoNoNoNoNoNo CVE-2026-84524 FontParser Processing a maliciously crafted font file may lead to unexpected app termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84569 Foundation An app may be able to access sensitive user data TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-86911 Foundation A malicious app may be able to bypass clickjacking protections for secure prompts TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84618 Game Center An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84533 Heimdal An attacker in a privileged network position may be able to modify network traffic TBDTBD YesNoYesNoNoYesYesNoNoNo CVE-2026-64714 ImageIO Processing a maliciously crafted image may lead to a denial-of-service TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84564 ImageIO Processing a maliciously crafted image may result in disclosure of process memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-86869 ImageIO Processing a maliciously crafted image may lead to unexpected app termination TBDTBD NoYesYesNoNoNoNoNoNoNo CVE-2026-43743 IOGPUFamily An app may be able to cause unexpected system termination TBDTBD NoYesNoYesNoNoNoNoNoNo CVE-2026-65398 IOMobileFrameBuffer An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesNoYesNoNoYesYesYesNoNo CVE-2026-65354 iWork A malicious app may be able to break out of its sandbox TBDTBD YesNoYesNoNoNoNoNoNoNo CVE-2026-28935 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD NoNoNoNoYesYesYesYesNoNo CVE-2026-28968 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-43790 Kernel A remote attacker may be able to cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65358 Kernel An app may be able to cause unexpected system termination TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-65359 Kernel A local user may be able to cause unexpected system termination or read kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-65360 Kernel An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-65369 Kernel A malicious application may bypass Gatekeeper checks TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65371 Kernel An app may be able to disclose kernel memory TBDTBD NoNoNoNoYesNoNoNoNoNo CVE-2026-65377 Kernel An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84507 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84530 Kernel An app may be able to disclose kernel memory TBDTBD YesYesYesYesNoYesYesYesNoNo CVE-2026-84544 Kernel Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84549 Kernel Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84558 Kernel An app may be able to cause unexpected system termination TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84561 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84566 Kernel A local attacker may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-84602 Kernel An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84622 Kernel An app with root privileges may be able to read uninitialized kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84514 Kext Management An app may be able to modify protected parts of the file system TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84556 Keychain Access An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65382 LaunchServices An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-86870 libarchive Processing a maliciously crafted file may lead to unexpected app termination TBDTBD YesYesYesNoNoNoYesYesNoNo CVE-2026-84577 libxpc An app may be able to bypass sandbox restrictions TBDTBD NoNoYesYesNoNoNoNoNoNo CVE-2026-43787 Mail An attacker in a privileged network position may be able to leak sensitive user information TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84573 Mail An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84628 MediaRemote A sandboxed app may be able to access the System Keychain TBDTBD YesNoYesNoNoYesYesYesNoNo CVE-2026-86924 MobileAccessoryUpdater Connecting a malicious accessory may cause unexpected system termination TBDTBD YesYesYesYesNoNoNoNoNoNo CVE-2026-65411 MobileBackup An app may be able to modify protected parts of the file system TBDTBD YesYesNoNoNoNoNoYesNoNo CVE-2026-84598 MobileBackup An attacker with physical access to a trust-paired device may be able to read and write arbitrary files TBDTBD YesYesNoNoNoNoNoNoNoNo CVE-2026-84497 Model I/O Opening a maliciously crafted file may lead to unexpected process termination TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-84615 Music An app may be able to access sensitive user data TBDTBD YesYesNoNoNoYesNoYesNoNo CVE-2026-43695 NetworkExtension An app may be able to access sensitive user data TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-84585 NetworkExtension An app may be able to access local network devices without user consent TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84626 NetworkExtension An app may be able to identify what other apps a user has installed TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-86902 NSDocument An app may be able to access sensitive user data TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84629 Photos Storage An app may be able to fingerprint the user TBDTBD YesNoNoNoNoYesYesYesNoNo CVE-2026-84623 Power Management An app may be able to fingerprint the device TBDTBD YesYesNoNoNoNoNoNoNoNo CVE-2026-84578 quarantine An app may be able to break out of its sandbox TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84580 quarantine An app may be able to break out of its sandbox TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84548 Quick Look Processing a maliciously crafted document may lead to an out-of-bounds read TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-28966 RealityKit Processing a maliciously crafted file may lead to unexpected app termination TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-84532 RealityKit Opening a maliciously crafted file may cause unexpected process termination or disclose process memory TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-65403 Reminders An app may be able to access sensitive user data TBDTBD YesYesYesYesYesNoYesYesNoNo CVE-2026-86897 Safe Browsing An app may be able to access sensitive user data TBDTBD YesYesYesNoNoNoNoYesYesNo CVE-2026-65380 Sandbox An app may be able to access protected user data TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84551 Sandbox An app may be able to bypass network restrictions TBDTBD YesNoYesNoNoNoYesYesNoNo CVE-2026-84603 Sandbox Profiles An app may be able to access sensitive user data TBDTBD YesNoNoNoNoNoYesYesNoNo CVE-2026-84625 Sandbox Profiles An app may be able to fingerprint the user TBDTBD YesNoYesNoNoNoYesYesNoNo CVE-2026-43697 SceneKit Processing a maliciously crafted 3D file may lead to an out-of-bounds read TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84526 SceneKit Processing a maliciously crafted 3D scene may lead to unexpected process termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84546 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84620 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84531 Security Processing maliciously crafted NTLM input may lead to unexpected app termination TBDTBD YesNoYesNoNoNoNoNoNoNo CVE-2026-86881 Security An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84600 Shortcuts A malicious shortcut may be able to send messages without user confirmation TBDTBD YesNoYesNoNoYesYesYesNoNo CVE-2026-86884 Siri An app may be able to access sensitive user data TBDTBD YesNoYesNoNoYesYesNoNoNo CVE-2026-86890 Siri Suggestions An attacker with physical access to a locked device may be able to view sensitive user information TBDTBD YesYesNoNoNoNoNoNoNoNo CVE-2026-65376 SMB An app may be able to cause unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84509 SMB Connecting to a malicious SMB server may lead to unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84609 Software Update An app may be able to modify protected system files TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-65361 SoftwareUpdate An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65378 Spotlight An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84621 Spotlight An app may be able to access sensitive user data TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-86892 SpringBoard An app may be able to cause a denial-of-service TBDTBD YesYesNoNoNoNoNoYesNoNo CVE-2026-65345 Storage An app may be able to access user-sensitive data TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-65348 Storage An app may be able to modify protected parts of the file system TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-43791 StorageKit An app may be able to read arbitrary files TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84513 Symptom Framework A malicious application may be able to determine a user's current location TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-65383 System Settings An app may bypass Gatekeeper checks TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-86909 System Settings An app may be able to bypass Gatekeeper checks TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84527 TCC An app may be able to access sensitive user data TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-84589 TCC An app may be able to modify Privacy preferences TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-86886 TCC An app may be able to modify protected system files TBDTBD YesYesNoNoNoNoYesNoNoNo CVE-2026-65329 Telephony An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic TBDTBD YesNoNoNoNoNoNoNoNoNo CVE-2026-86887 Time Zone An app may be able to bypass certain Privacy preferences TBDTBD YesYesNoNoNoNoNoYesNoNo CVE-2026-43696 Touch Bar An app may be able to capture Touch Bar content without authorization TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84572 udf An app may be able to cause unexpected system termination or read kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-28899 WebDAV An app may bypass Gatekeeper checks TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65375 WebDAV An app may be able to cause unexpected system termination TBDTBD NoNoYesNoYesNoNoNoNoNo CVE-2026-84635 WebKit Processing maliciously crafted web content may lead to an unexpected process termination TBDTBD YesNoYesNoNoYesYesYesYesNo CVE-2026-86898 WebKit Opening a maliciously crafted webarchive file may lead to universal cross-site scripting TBDTBD YesNoYesNoNoNoNoYesYesNo CVE-2026-84636 Wi-Fi Connectivity An app may be able to access sensitive user data TBDTBD YesNoNoNoNoYesYesYesNoNo CVE-2026-43674 Wi-Fi3 An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication TBDTBD YesNoNoNoNoNoNoNoNoNo We’ll continue these macOS updates if people find them useful. Stay tuned for the regularly schedule Patch Tuesday blog covering Adobe and Microsoft.
Qualys Security Blog VulnOracle Critical Security Patch Update, September 2026 Review
Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. Out of the 673 security updates published, a total of 104 […]
CISA Advisories Breach
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
CISA Advisories Policy
Using Cyber Decoys to Strengthen Detection and Response
CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly. Cyber decoys complement Zero Trust by: Supporting continuous monitoring and verification, Creating high-fidelity alerts for suspicious activity, Reducing alert fatigue, and Helping defenders detect post-compromise activity, including adversary LOTL techniques. This guidance introduces decoy concepts—including tripwires, breadcrumbs, and honeytokens—and uses the MITRE Engage™ and MITRE ATT&CK® frameworks to provide practical, low-complexity steps for planning, implementing, and refining decoy operations. For additional information, visit CISA’s Best Practices for MITRE ATT&CK Mapping. Note: CISA is committed to providing access to our web pages and documents for individuals with disabilities, both members of the public and federal employees. If the format of any elements or content within this document interferes with your ability to access the information, as defined in the Rehabilitation Act, please email contact@cisa.dhs.gov. To enable us to respond in a manner most helpful to you, please indicate the nature of your accessibility problem and the preferred format in which to receive the material. CISA will update Using Cyber Decoys to Strengthen Detection and Response when the 508 compliance has been completed.
CISA Advisories Breach
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Palo Alto Unit 42 MalwareAtomic macOS (AMOS) Stealer Activity
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.
AWS Security Blog PolicyAWS STS simplifies session token size limits and adds session token size monitoring
AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token size limits with a single token size limit of 4,096 bytes. STS now reports session token size in API responses, […]
AWS Security Blog VulnArchitecting resilient authentication with Amazon Cognito multi-Region replication
Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applications. As your business scales across geographies, ensuring authentication is always available becomes a core architectural requirement. However, building multi-Region authentication has traditionally required complex custom replication solutions that […]
Qualys Security Blog VulnBefore You Patch. Why Patch Reliability Matters for Confident Deployment
Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and security teams focus on deeper […]
AWS Security Blog VulnOperationalizing least privilege: Automate IAM remediation through your CI/CD pipeline
The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader permissions than strictly necessary; it’s faster to get things working, and the plan is always to tighten permissions later. But later rarely comes. Permissions accumulate, AWS Identity and Access […]
Qualys Security Blog VulnAutomate Asset Isolation: Your Last Resort to Meet Remediation Deadlines
Executive Summary Remediation deadlines slip for reasons outside your control: a patch does not exist yet, a patch is delayed, or a remediation attempt fails. The outcome is the same either way: the host stays unpatched and stays on the network. TruRisk Eliminate closes that window by isolating the host automatically the moment your deadline […]
Wiz Blog VulnInvesting Together: Wiz Defend and Google Security Operations
Continuing to deepen the integration between Wiz Defend and Google Security Operations, helping teams work faster wherever they choose to investigate
CISA Advisories Breach
Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers
Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt hybrid and multi-cloud environments, single sign-on, federation, and application programming interface (API)-based access increasingly depend on signed tokens and assertions that adversaries may target for forgery, theft, and misuse to move laterally across enterprise networks and access sensitive data. This final report updates the initial public draft and incorporates feedback on token validation, secrets management, and detection at scale, as well as input from government and industry experts that CISA gathered through its Joint Cyber Defense Collaborative. The report expands on NIST Special Publication Security and Privacy Controls for Information Systems and Organizations and supports Executive Order 14306 on secure software development practices. It provides architectural considerations and emphasizes the importance of Secure by Design principles for interoperable defense across cloud environments.
CISA Advisories Vuln
Digital Watchdog VMAX DVR and NVR Product Lineups
View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point. The following versions of Digital Watchdog VMAX DVR and NVR Product Lineups are affected: VMAX A1 G4 DVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX IP G4 NVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX A1 PLUS vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VA1G4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VG4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) CVSS Vendor Equipment Vulnerabilities v3 9.6 Digital Watchdog Digital Watchdog VMAX DVR and NVR Product Lineups Missing Authentication for Critical Function, Use of Hard-coded Credentials, Missing Authorization, Predictable Seed in Pseudo-Random Number Generator (PRNG) Background Critical Infrastructure Sectors: Commercial Facilities, Government Services and Facilities, Healthcare and Public Health, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-68953 The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests. View CVE Details Affected Products Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:known_affected Remediations MitigationDigital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at: https://digital-watchdog.com/downloads/ Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-66890 The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable. View CVE Details Affected Products Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:known_affected Remediations MitigationDigital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at: https://digital-watchdog.com/downloads/ Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.6 CRITICAL CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 9.4 CRITICAL CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVE-2026-68070 The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command. View CVE Details Affected Products Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:known_affected Remediations MitigationDigital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at: https://digital-watchdog.com/downloads/ Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-68950 The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable. View CVE Details Affected Products Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:known_affected Remediations MitigationDigital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at: https://digital-watchdog.com/downloads/ Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-66887 The affected products are missing authorization on state-changing CGIs and session checks are not performed. View CVE Details Affected Products Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:known_affected Remediations MitigationDigital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at: https://digital-watchdog.com/downloads/ Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.6 CRITICAL CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 9.4 CRITICAL CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVE-2026-66372 The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space. View CVE Details Affected Products Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:known_affected Remediations MitigationDigital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at: https://digital-watchdog.com/downloads/ Relevant CWE: CWE-337 Predictable Seed in Pseudo-Random Number Generator (PRNG) Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N 4.0 7.6 HIGH CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Acknowledgments Scot Berner of TrustedSec reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely. Revision History Initial Release Date: 2026-09-15 Date Revision Summary 2026-09-15 1 Initial Publication Legal Notice and Terms of Use
CISA Advisories Vuln
mySCADA myPRO Manager
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem. The following versions of mySCADA myPRO Manager are affected: mySCADA myPRO Manager <=2.1 (CVE-2026-73807, CVE-2026-82567) CVSS Vendor Equipment Vulnerabilities v3 9.8 mySCADA Technologies mySCADA myPRO Manager Missing Authorization, Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Food and Agriculture, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Czechia Vulnerabilities Expand All + CVE-2026-73807 The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions. View CVE Details Affected Products mySCADA myPRO Manager Vendor:mySCADA Technologies Product Version:mySCADA Technologies mySCADA myPRO Manager: <=2.1 Product Status:known_affected Remediations MitigationmySCADA Technologies has addressed these issues in Version 2.2 and recommends that users update to the latest version. Users are notified in mySCADA Pro Manager about the availability of a new version if the device is connected to the internet. Otherwise, users can download the mySCADA Pro Manager from the webpage.https://www.myscada.org/downloads/mySCADAPROManager/ Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-82567 The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number and message from a request and sending the specified SMS message. An unauthenticated attacker with network access to the notification gateway could exploit this vulnerability to send arbitrary SMS messages through the connected modem. View CVE Details Affected Products mySCADA myPRO Manager Vendor:mySCADA Technologies Product Version:mySCADA Technologies mySCADA myPRO Manager: <=2.1 Product Status:known_affected Remediations MitigationmySCADA Technologies has addressed these issues in Version 2.2 and recommends that users update to the latest version. Users are notified in mySCADA Pro Manager about the availability of a new version if the device is connected to the internet. Otherwise, users can download the mySCADA Pro Manager from the webpage.https://www.myscada.org/downloads/mySCADAPROManager/ Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.3 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 4.0 5.3 MEDIUM CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N Acknowledgments Shirshak Secnora OÜ reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-15 Date Revision Summary 2026-09-15 1 Initial Publication Legal Notice and Terms of Use
CISA Advisories Vuln
Schneider Electric SCADAPack x70 Products
View CSAF Summary Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality. The following versions of Schneider Electric SCADAPack x70 Products are affected: SCADAPack 47x vers:all/* (CVE-2026-81861) SCADAPack 47xi vers:all/* (CVE-2026-81861) SCADAPack 47xd vers:all/* (CVE-2026-81861) SCADAPack 470R vers:all/* (CVE-2026-81861) SCADAPack 57x vers:all/* (CVE-2026-81861) SCADAPack 3xx vers:all/* (CVE-2026-81861) SCADAPack 32 vers:all/* (CVE-2026-81861) CVSS Vendor Equipment Vulnerabilities v3 6.5 Schneider Electric Schneider Electric SCADAPack x70 Products Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All + CVE-2026-81861 There is an insufficiently protected credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality. View CVE Details Affected Products Schneider Electric SCADAPack x70 Products Vendor:Schneider Electric Product Version:SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R, SCADAPack 57x, SCADAPack 3xx, SCADAPack 32 Product Status:known_affected Remediations MitigationImplement the Role-Based Access Control (RBAC) feature and follow the SCADAPack documentation sections Security Guidelines for Administrators and Working with Role-Based Access Control. RBAC is the recommended access control mechanism for SCADAPack 47x devices and should be used in place of the Secure Lock feature. The Secure Lock feature is legacy functionality retained for backward compatibility with existing deployments and should only be used where required to support legacy system requirements. Consult the SCADAPack Cybersecurity Guide, including the SCADAPack Hardening and Secured Communication sections. In addition, apply the following standard practices to reduce the risk of exploitation: Configure network segmentation to restrict access between trusted and untrusted networks. Enable and implement the RTU firewall service to restrict unauthorized access to device services and reduce the attack surface. Documentation available in RemoteConnect and SCADAPack x70 Utilities | Schneider Electric https://www.se.com/ww/en/download/document/RemoteConnect/ MitigationEnsure setup of network segmentation to restrict access between trusted and untrusted networks and implementation of the RTU Firewall Service to restrict unauthorized access to services. Consult the SCADAPack Cybersecurity Guide, including the SCADAPack Hardening and Secured Communication sections. In addition, implement all best practices referenced in the SCADAPack Cybersecurity Guide. Documentation available in RemoteConnect and SCADAPack x70 Utilities | Schneider Electric https://www.se.com/ww/en/download/document/RemoteConnect/ Mitigation For more information see the associated Schneider Electric security advisory SEVD-2026-251-03 Insufficiently Protected Credentials vulnerability on SCADAPack x70 Products PDF Version, CSAF Version. Relevant CWE: CWE-522 Insufficiently Protected Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Acknowledgments Abhinav Agarwal reported this vulnerability to CISA. General Security Recommendations Schneider Electric strongly recommends the following industry cybersecurity best practices: Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks. Place all controllers in locked cabinets and never leave them in the “Program” mode. Never connect programming software to any network other than the network intended for that device. Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks. Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation. Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet. When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices. For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document. For More Information This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp LEGAL DISCLAIMER THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION About Schneider Electric Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in Sustainability and Efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-251-03 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-09-08 Date Revision Summary 2026-09-08 1 Original Release 2026-09-15 2 Initial CISA Republication of Schneider Electric SEVD-2026-251-03 advisory Legal Notice and Terms of Use
CISA Advisories Vuln
Siemens Teamcenter
View CSAF Summary A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Teamcenter are affected: Teamcenter V2412 vers:intdot/<2412.0013 (CVE-2026-58113) Teamcenter V2506 vers:intdot/<2506.0010 (CVE-2026-58113) Teamcenter V2512 vers:intdot/<2512.2607 (CVE-2026-58113) Teamcenter V2606 vers:intdot/<2606.2607 (CVE-2026-58113) CVSS Vendor Equipment Vulnerabilities v3 6.1 Siemens Siemens Teamcenter Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-58113 Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session. View CVE Details Affected Products Siemens Teamcenter Vendor:Siemens Product Version:Teamcenter V2412 < V2412.0013, Teamcenter V2506 < V2506.0010, Teamcenter V2512 < V2512.2607, Teamcenter V2606 < V2606.2607 Product Status:known_affected Remediations Vendor fixUpdate to V2412.0013 or later versionhttps://support.sw.siemens.com/product/282219420/ Vendor fixUpdate to V2506.0010 or later versionhttps://support.sw.siemens.com/product/282219420/ Vendor fixUpdate to V2512.2607 or later versionhttps://support.sw.siemens.com/product/282219420/ Vendor fixUpdate to V2606.2607 or later versionhttps://support.sw.siemens.com/product/282219420/ Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Acknowledgments Enzo Alvarez from Bishop Fox reported this vulnerability to Siemens. General Recommendations As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for industrial security and following recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Additional information on industrial security by Siemens can be found on the Siemens industrial security webpage For more information see the associated Siemens security advisory SSA-157465 in HTML and CSAF. Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-157465 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-09-08 Date Revision Summary 2026-09-08 1 Publication Date 2026-09-15 2 Initial CISA Republication of Siemens ProductCERT SSA-157465 advisory Legal Notice and Terms of Use
CISA Advisories Vuln
Siemens Mendix SAML
View CSAF Summary Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version. The following versions of Siemens Mendix SAML are affected: Mendix SAML (Mendix 10 compatible) vers:intdot/<4.2.3 (CVE-2026-80465) Mendix SAML (Mendix 11 compatible) vers:intdot/<4.2.3 (CVE-2026-80465) Mendix SAML (Mendix 9.24 compatible) vers:intdot/<3.6.27 (CVE-2026-80465) CVSS Vendor Equipment Vulnerabilities v3 8.7 Siemens Siemens Mendix SAML Improper Verification of Cryptographic Signature Background Critical Infrastructure Sectors: Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-80465 Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations. View CVE Details Affected Products Siemens Mendix SAML Vendor:Siemens Product Version:Mendix SAML (Mendix 10 compatible) < V4.2.3, Mendix SAML (Mendix 11 compatible) < V4.2.3, Mendix SAML (Mendix 9.24 compatible) < V3.6.27 Product Status:known_affected Remediations Vendor fixUpdate to V3.6.27 or later versionhttps://marketplace.mendix.com/link/component/1174 Vendor fixUpdate to V4.2.3 or later versionhttps://marketplace.mendix.com/link/component/1174 Vendor fixUpdate to V4.2.3 or later versionhttps://marketplace.mendix.com/link/component/1174 Relevant CWE: CWE-347 Improper Verification of Cryptographic Signature Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.7 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N Acknowledgments Siemens ProductCERT reported this vulnerability to CISA. General Recommendations As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security, and following the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories For more information see the associated Siemens security advisory SSA-887643 in HTML and CSAF. Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-887643 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-09-03 Date Revision Summary 2026-09-03 1 Publication Date 2026-09-15 2 Initial CISA Republication of Siemens ProductCERT SSA-887643 advisory Legal Notice and Terms of Use
CISA Advisories Vuln
Wärtsilä FOS-Onboard
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client. The following versions of Wärtsilä FOS-Onboard are affected: FOS-Onboard 5.07.0923.01 (CVE-2026-78225, CVE-2026-81855) CVSS Vendor Equipment Vulnerabilities v3 9.1 Wärtsilä Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Finland Vulnerabilities Expand All + CVE-2026-78225 A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard. View CVE Details Affected Products Wärtsilä FOS-Onboard Vendor:Wärtsilä Product Version:Wärtsilä FOS-Onboard: 5.07.0923.01 Product Status:known_affected Remediations MitigationWärtsilä states that the vulnerabilities are not exploitable when the product is installed as recommended, and has developed a security patch. Users are also directed to contact Wärtsilä to obtain and install the patch. To obtain and install the latest patch, contact Wärtsilä: https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 9.5 CRITICAL CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVE-2026-81855 A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard. View CVE Details Affected Products Wärtsilä FOS-Onboard Vendor:Wärtsilä Product Version:Wärtsilä FOS-Onboard: 5.07.0923.01 Product Status:known_affected Remediations MitigationWärtsilä states that the vulnerabilities are not exploitable when the product is installed as recommended, and has developed a security patch. Users are also directed to contact Wärtsilä to obtain and install the patch. To obtain and install the latest patch, contact Wärtsilä: https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Acknowledgments Cydome Security Ltd reported these vulnerabilities to Wärtsilä and CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-15 Date Revision Summary 2026-09-15 1 Initial Publication Legal Notice and Terms of Use
CISA Advisories Vuln
Siemens Reyrolle 7SR5
View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version. The following versions of Siemens Reyrolle 7SR5 are affected: Reyrolle 7SR5 vers:intdot/<2.70 (CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650, CVE-2026-62652, CVE-2026-62653, CVE-2026-62654) CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens Reyrolle 7SR5 Integer Overflow or Wraparound, Improper Neutralization of Delimiters, Use of Out-of-range Pointer Offset, Missing Authentication for Critical Function, Insufficient Entropy, Improper Input Validation, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Authentication Bypass Using an Alternate Path or Channel, Insertion of Sensitive Information Into Debugging Code, Download of Code Without Integrity Check Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2024-42384 Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-190 Integer Overflow or Wraparound Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2024-42385 Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-140 Improper Neutralization of Delimiters Metrics CVSS Version Base Score Base Severity Vector String 3.1 4 MEDIUM CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H CVE-2024-42386 Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-823 Use of Out-of-range Pointer Offset Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.2 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H CVE-2024-42391 Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-823 Use of Out-of-range Pointer Offset Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N CVE-2024-42392 Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-140 Improper Neutralization of Delimiters Metrics CVSS Version Base Score Base Severity Vector String 3.1 4 MEDIUM CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H CVE-2026-62645 Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2026-62646 A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-331 Insufficient Entropy Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.4 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2026-62647 A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easily predict the generated values and impersonate a legitimate authenticated user, potentially gaining unauthorized access to the device. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-20 Improper Input Validation Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.4 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2026-62648 The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denial-of-service condition. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-62649 The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated remote attacker to cause the entire device to crash and reboot, resulting in a denial-of-service condition. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-770 Allocation of Resources Without Limits or Throttling Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-62650 Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed through manipulation of request data. This could allow an authenticated, low-privileged remote attacker to escalate privileges to an administrative level. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-288 Authentication Bypass Using an Alternate Path or Channel Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2026-62652 The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-215 Insertion of Sensitive Information Into Debugging Code Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2026-62653 The input received over a proprietary communication protocol that is exposed when the device is placed into a special firmware-update mode is not properly validated, resulting in a memory corruption condition. This could allow an unauthenticated attacker with physical access to the device to cause a crash and potentially execute arbitrary code on the device. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2026-62654 A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a network server without verifying its authenticity or integrity. This could allow an attacker with physical access to the device to upload and execute arbitrary, unsigned code. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-494 Download of Code Without Integrity Check Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Siemens ProductCERT reported these vulnerabilities to CISA. General Recommendations Operators of critical power systems (e.g. TSOs or DSOs) worldwide are usually required by regulations to build resilience into the power grids by applying multi-level redundant secondary protection schemes. It is therefore recommended that the operators check whether appropriate resilient protection measures are in place. The risk of cyber incidents impacting the grid's reliability can thus be minimized by virtue of the grid design. Siemens strongly recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. As a general security measure Siemens strongly recommends protecting network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to our operational guidelines in order to run the devices in a protected IT environment. Recommended security guidelines can be found at: https://www.siemens.com/gridsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Additional information on industrial security by Siemens can be found on the Siemens industrial security webpage For more information see the associated Siemens security advisory SSA-142885 in HTML and CSAF. Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-142885 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-09-08 Date Revision Summary 2026-09-08 1 Publication Date 2026-09-15 2 Initial CISA Republication of Siemens ProductCERT SSA-142885 advisory Legal Notice and Terms of Use
CISA Advisories Vuln
CareCam CM2507
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored credentials. The following versions of CareCam CM2507 are affected: HMT.CM2507 Firmware v251211.1507 (CVE-2026-88259, CVE-2026-84398, CVE-2026-84400, CVE-2026-81305, CVE-2026-85478, CVE-2026-85497, CVE-2026-81321) CVSS Vendor Equipment Vulnerabilities v3 7.5 CareCam CareCam CM2507 Missing Authentication for Critical Function, Empty Password in Configuration File, Inclusion of Functionality from Untrusted Control Sphere, Use of Password Hash With Insufficient Computational Effort, Cleartext Storage of Sensitive Information Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-88259 CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video. View CVE Details Affected Products CareCam CM2507 Vendor:CareCam Product Version:CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:known_affected Remediations MitigationCareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-84398 CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information. View CVE Details Affected Products CareCam CM2507 Vendor:CareCam Product Version:CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:known_affected Remediations MitigationCareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information. Relevant CWE: CWE-258 Empty Password in Configuration File Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-84400 CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the service remotely accessible, increasing the risk of unauthorized administrative access. View CVE Details Affected Products CareCam CM2507 Vendor:CareCam Product Version:CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:known_affected Remediations MitigationCareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.1 LOW CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N 4.0 2.3 LOW CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-81305 CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code in the security context of the affected device. View CVE Details Affected Products CareCam CM2507 Vendor:CareCam Product Version:CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:known_affected Remediations MitigationCareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information. Relevant CWE: CWE-829 Inclusion of Functionality from Untrusted Control Sphere Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 7 HIGH CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-85478 A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt the normal boot process and access functionality that permits inspection or modification of boot configuration, firmware data, and software loaded by the device. View CVE Details Affected Products CareCam CM2507 Vendor:CareCam Product Version:CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:known_affected Remediations MitigationCareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.5 LOW CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N 4.0 2.4 LOW CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-85497 CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware. View CVE Details Affected Products CareCam CM2507 Vendor:CareCam Product Version:CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:known_affected Remediations MitigationCareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information. Relevant CWE: CWE-916 Use of Password Hash With Insufficient Computational Effort Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-81321 CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key. View CVE Details Affected Products CareCam CM2507 Vendor:CareCam Product Version:CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:known_affected Remediations MitigationCareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information. Relevant CWE: CWE-312 Cleartext Storage of Sensitive Information Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Ben Law reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-15 Date Revision Summary 2026-09-15 1 Initial Publication Legal Notice and Terms of Use
Trail of Bits Vuln1Password's AI patching benchmark is misleading
1Password’s FLAWED report, published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of the time. That figure includes experiments that deliberately instructed agents to apply the wrong fix, along with experiments in which agents could not compile or test their patches. The report risks making defenders less effective by discouraging them from using technology that could help them fix more vulnerabilities. Teams that take its headline at face value may leave repairable vulnerabilities unaddressed. We want our work to help defenders fix more vulnerabilities. This post shares real-world data on human and agent patch quality from our consulting projects and Patch the Planet. We’re also releasing two agent skills: post-patch-validation to help agents test fixes, and review-walkthrough to help engineers review them. How the experiment produces a misleading headline Our review of 1Password’s code and data found four choices that make its 26% clean-fix rate a misleading guide to ordinary patching work.1 The sample was selected for difficult fixes. The authors chose six vulnerabilities because their fixes were complex. Clean-fix rates ranged from 3% to 60% across those bugs, so the average depends heavily on which vulnerabilities made the list.2 Two prompts tell agents to apply the wrong fix. Those prompts account for 22% of the data. Combining them with ordinary repair attempts makes the reported rate depend partly on how often the researchers chose to give agents bad advice. More than a third of the trials prohibit testing. One evaluation mode prevents agents from building or running code and accounts for 36% of the data. The headline combines those trials with experiments in which agents could test their patches and act on the results. The models ran at different reasoning settings. GPT-5.5 ran at medium effort and Opus 4.8 at high. These were the tools’ defaults. Neither model was tested at its highest available setting, and the authors did not measure how increasing effort affected the results. 1Password’s headline also obscures a useful result in its own data. We reanalyzed the patches and recorded test results published with the study, keeping trials where agents could run code and were not instructed to apply the wrong fix. In those trials, 2,634 of 3,067 patches generated by 1Password’s models (86%) blocked the supplied exploit. We excluded runs that the study classified as having consulted the upstream fix. Blocking that exploit does not establish a complete repair, but these results show useful patching capability under reasonable working conditions that the headline fails to convey. The instructions and grading introduce further problems, several of which Davi Ottenheimer has also highlighted: The stopping rule and grading criteria disagree. Agents given a proof-of-concept exploit were instructed to stop once their patch defeated it. The grader then evaluated vulnerable paths that the supplied exploit did not exercise. The grading penalizes intended behavior changes. Agents were told to leave existing tests untouched, even though a correct fix can require updating tests to reflect changed behavior. We found that 8% of ActiveMQ verdicts penalized an intended behavior change as a regression. The automated grades disagree with human review. Models grading their own patches matched human reviewers on the full five-category outcome in 65.9% of reviewed cases. Agreement was 87.7% for whether the original bug was fixed and 70.5% for whether new bugs were introduced. (Table 24) Changing the reviewer changes the result. The two models assigned different outcomes to 36.8% of the same patches. The headline averages their assessments. (Table 20) The Linux reference fix contains a vulnerability. The authors found 248 generated patches that repeated an off-by-one error in the upstream fix. The automated grader caught that new vulnerability in only 24 of them. (Section 4.4) The Chromium grader accepts incomplete repairs. It marked many patches as clean even though they left a use-after-free vulnerability in a callback. (Section 4.9) The grading errors can penalize valid fixes and let vulnerable patches pass. Combined with the handpicked sample and deliberately bad instructions, they leave the report without a credible basis for its headline. Defenders should not take 1Password’s headline rate seriously as a measure of AI patching ability. Developers get one in eight fixes wrong under ideal conditions Understanding agent failures also requires understanding how often developers submit incomplete fixes. Our security consulting work gives us a detailed record of how developers repair vulnerabilities in their own software. We give clients detailed vulnerability reports, then conduct a “fix review” to check whether their proposed patches fully resolve the issues. Our records connect each vulnerability to the developer’s first proposed fix and our assessment of whether it worked. They preserve unsuccessful attempts that developers revise before an issue is considered resolved. We reviewed the first fixes submitted for 2,265 vulnerabilities across 236 Trail of Bits security assessments from 2024 to 2026. The developers maintained the affected software, had detailed reports from our engineers, and knew we would review their patches. Even under those favorable conditions, 283 first fixes failed to fully resolve the reported issue: 12.5%, or one in eight. Figure showing first fix submission outcomes Accounting for multiple fixes from the same assessment, the 95% confidence interval is 10.5% to 14.5%. Sometimes we point out a mistake in a client’s patch during an informal conversation, and they correct it before the formal fix review. Those early failures may never appear in the review record, so our data can undercount failed first attempts. We also excluded cases where the available records did not establish whether the fix worked. A direct comparison with agents would require the same tasks and working conditions. What happened to our patches in real projects Through Patch the Planet, our joint initiative with OpenAI, Trail of Bits has co-authored hundreds of patches for widely used open-source projects. Agents wrote the patches with engineers directing the work and checking the results. Project maintainers then decided whether to merge, revise, or reject each submission. How maintainers reviewed Patch the Planet patches We examined the public review history of every Patch the Planet submission in our dataset that maintainers had merged or closed by September 14, 2026: 186 pull requests. 1Password’s benchmark used six vulnerabilities selected because their fixes were complex. Maintainers merged 126 of our 186 pull requests, an acceptance rate of 67.7%.3 In 91 of those 126 pull requests (72.2%), maintainers accepted the security fix we originally proposed. Review outcome PRs % of merged PRs Total merged 126 100% Accepted with no security-relevant revision observed 91 72.2% Accepted with security-relevant revision observed 33 26.2% Indeterminate 2 1.6% Table 1: Changes requested by maintainers for 126 merged Patch the Planet pull requests. Security-related revisions include repairs to a proposed fix and expansions of its security coverage. Maintainer acceptance does not establish that every patch is correct. Maintainers closed the other 60 submissions without merging them. Most were superseded by other work or declined for policy, process, scope, or maintenance reasons. Four were explicitly rejected on technical grounds. Reason for closure PRs % of closed PRs Total closed without merge 60 100% Superseded, reimplemented, or re-landed elsewhere 36 60.0% Policy, process, scope, or maintenance reasons 14 23.3% Duplicate or convergent with another fix 3 5.0% Explicitly rejected on technical grounds 4 6.7% Other or indeterminate 3 5.0% Table 2: Reasons maintainers closed 60 Patch the Planet pull requests without merging One of those closed submissions was our freenginx patch. A maintainer and an agent introduced the same freenginx crash 1Password’s case study examines a Patch the Planet fix for a memory-safety bug in freenginx’s embedded Perl module. An agent wrote our patch under the direction of a Trail of Bits engineer. It left one vulnerable code path open and introduced a new crash during request cleanup. The paper’s criticism of our patch is correct. The maintainer closed our pull request and committed a separate fix. That fix covered all three vulnerable code paths but introduced the same crash during cleanup. The paper documents the maintainer’s regression too. Both authors encountered the same trap. The original bug allowed Perl to destroy a callback before freenginx used it. Both fixes kept the callback alive so freenginx could use it later. But if the request timed out first, freenginx would make the request unusable and then release the callback. Releasing it could run Perl code that still tried to use the request, crashing the worker. Both authors missed a problem their fix could cause later, during cleanup. Catching it required looking beyond the original bug to what happened when a request ended early. Two authors, one human and one agent, working separately, made the same mistake on the same bug. Readers deciding whether to use agents need to know how their failures compare with those of human developers. Establishing which is more reliable requires measuring both under comparable conditions. We checked what happened after our patches were merged We examined about 33,500 subsequent commits in Patch the Planet projects. When a later commit changed a file our patch had modified, we investigated whether it fixed a problem our patch had introduced. For each suspected regression, an agent attempted to demonstrate its impact with a proof of concept. Other agents and our engineers then challenged the findings. The review found at least ten functional bugs; four build, test, or release automation bugs; and one performance bug. It found no exploitable security vulnerabilities. Two examples illustrate the problems we identified: In go-jose, PR #240 fixed a missing-header crash but exposed an existing validation gap, allowing encrypted messages to succeed even when their key length contradicted the declared algorithm. PR #266 added explicit key-length checks before decryption. In Noble FROST, PR #250 returned cached round-two results without first checking whether a retry contained the same authenticated transcript. Changed or stale retry data could therefore bypass that check. The maintainer corrected the behavior by validating retries against the original transcript before returning cached results. We are extending this investigation to every patch we authored, including patches with maintainer contributions. The findings will help us add checks that catch these failures before we submit future patches. Agent skills for better security patches We are releasing two agent skills alongside this post: post-patch-validation to help agents test security fixes, and review-walkthrough to help engineers review code changes. Post-patch-validation is a new skill we wrote to help agents catch incomplete fixes and regressions before submitting patches for review. It was not used in the Patch the Planet work described above. The skill starts with a vulnerability report and the code before and after the patch. It guides the agent through four tasks: Reproduce the original bug. The agent writes a check that must fail on the vulnerable code and pass on the patched version. A test that passes on both revisions cannot demonstrate a fix. Test another path to the same failure. The skill requires at least one distinct variant based on the bug’s root cause, such as a different caller or a cleanup path. Check for regressions and new vulnerabilities. It compares behavior that should remain unchanged and tests security properties around the modified code. The plan must also include project tests, a sanitizer check, or a bounded fuzzing run. Treat broken test runs as inconclusive. A failed build or missing dependency must not be mistaken for evidence that a vulnerability was reproduced. Failed checks give the agent specific problems to investigate and repair before submitting its patch. The skill saves the tests and results so maintainers can see what was checked. To try post-patch-validation, install the skill and give your agent the vulnerability report and the vulnerable and patched revisions: “Use post-patch-validation to validate the patch in HEAD against <vulnerable-commit>, using the vulnerability report in <report-path>.” Review-walkthrough helps engineers review the patches they are responsible for merging. It turns a branch’s complete diff into an interactive walkthrough that explains the changes in a logical reading order. Review findings appear beside the relevant code, where engineers can inspect them and draft their own comments. The walkthrough can also prepare a GitHub review for submission. Follow the quick start to generate a walkthrough for your branch. These releases join our other public agent skills for improving security patches: variant-analysis helps agents find related defects elsewhere in the codebase. property-based-testing helps them test behavior across generated inputs. mutation-testing helps them determine whether their tests detect incorrect behavior and identify missing assertions. We publish these methods so other teams can use them to examine and improve their own patches. What a useful patching benchmark should measure A useful patching benchmark should measure whether agents help developers produce correct fixes and how much review those fixes require. The principles in our 2018 guide to evaluating fuzzing research apply here: Choose a sample that matches the research question. Explain how the sample was chosen and which repair work it represents. Difficult cases can expose failure modes. General failure rates require a representative sample. Measure the effects of working conditions. Give agents appropriate tools and instructions. Report model configurations and test how reasoning settings affect results. Report misleading prompts and restricted tool access separately. Make correctness verifiable. Check that patches fix the vulnerability beyond the supplied exploit. Test for security, functional, and performance regressions. Validate grades against expert review and publish the tests, configurations, and results. Show how results vary. Report per-vulnerability outcomes and variation across repeated attempts. Repeating trials on the same bugs cannot establish that those bugs represent everyday patching. Measure what agents contribute to the repair process. Compare developers working with and without agents on comparable tasks and under comparable conditions. Measure initial patch quality and the review and revision needed to reach a correct fix. We are optimistic about AI’s usefulness to defenders. Through Patch the Planet, we are committing engineering time to fixing vulnerabilities alongside the people who maintain the affected software. We examine failures so we can improve our methods. We will keep putting agents to work on difficult security problems and making the tools and lessons public. We want other teams to test our conclusions and take these methods further. Our goal is to give maintainers without dedicated security teams the ability to find and fix vulnerabilities that would otherwise go unaddressed. The paper defines a clean fix as fully resolving the vulnerability without materially changing application behavior. ↩︎ The six-target mean has a standard error of about nine percentage points, which the report does not disclose. ↩︎ As of September 14, 2026, our dataset contained 240 public upstream pull requests. We excluded the 54 submissions still open from the outcome analysis. We count pull requests, each of which can contain more than one patch, and exclude maintainer-written replacements from our merged total. ↩︎
AWS Security Blog PolicyAWS Security Reference Architecture: A deep dive into PCI DSS compliance
Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive. This new guide extends the core AWS SRA to provide prescriptive, architecture-level guidance for organizations that store, process, or transmit cardholder data on AWS. Organizations subject to […]
Decipher VulnHere Come the AI-Generated BEC Scams
Messages delivered through legitimate third-party email infrastructure had C-suite sender display names, custom signatures, and direct approval notes.
Check Point Research Breach14th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a […] The post 14th September – Threat Intelligence Report appeared first on Check Point Research.
CISA Advisories Breach
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Palo Alto Unit 42 VulnUnmasking Cloud Identities: From Behavioral Clustering to Automated Detection
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42.
CISA Advisories Breach
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
CISA Advisories Breach
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Wiz Blog VulnArtifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329). Attackers are chaining these vulnerabilities to bypass authentication and gain administrative control.