Category: Vulnerabilities
CISA Warns of Critical Flaws in Daktronics Controller Firmware
Three vulnerabilities in Daktronics DMP and VFC-DMP controller firmware, including hard-coded credentials and unrestricted file upload, could give unauthenticated attackers full root-level…
Bad Epoll Linux Kernel Flaw Grants Root to Unprivileged Users, Affects Android
A newly disclosed Linux kernel vulnerability tracked as CVE-2026-46242 allows an ordinary unprivileged user to gain full root control. The flaw affects…
Seven Unpatched Flaws Found in FatFs Library Used Across Millions of Embedded Devices
Security firm runZero has disclosed seven vulnerabilities in FatFs, a widely embedded FAT/exFAT filesystem library present in firmware for cameras, drones, industrial…
Delta Electronics DVP12SE PLC Exposes Critical Unauthenticated Modbus Flaws
Two critical vulnerabilities in Delta Electronics DVP12SE PLCs allow unauthenticated remote attackers to manipulate control logic and flood the device into unavailability.…
FUXA SCADA/HMI Flaw Lets Attackers Bypass Auth via Path Tricks
A dot-segment path normalization bug in FUXA versions 1.3.1 and earlier allows unauthenticated remote attackers to enumerate users and roles through the…
CISA Warns of Four Vulnerabilities in Mitsubishi MELSOFT Update Manager
A bundled 7-Zip component in Mitsubishi Electric's MELSOFT Update Manager carries four flaws that could let a local attacker crash the software…
Schneider Electric EcoStruxure IT DCE Patched for XXE Info Disclosure
A medium-severity XXE vulnerability in Schneider Electric's EcoStruxure IT Data Center Expert allows authenticated users to read server-side files via crafted SOAP…
XZ Utils Flaw in B&R Industrial Panels Allows Remote Crash or Memory Corruption
A high-severity race condition in the XZ Utils multithreaded decoder affects eight B&R Industrial Automation panel and controller product lines, with fixes…
Schneider Electric RTUs Expose Credentials via Two High-Severity Flaws
CISA has published an advisory detailing two vulnerabilities in Schneider Electric EasyLogic T150 and Saitel DP remote terminal units that allow credential…
Critical Cursor AI Editor Flaws Enable OS-Level Remote Code Execution
Two vulnerabilities in the Cursor AI code editor, collectively dubbed DuneSlide, allow attackers to escape the IDE sandbox and execute arbitrary code…
Critical Cursor AI Editor Flaws Allow Prompt Injection to Escape Sandbox
Two near-perfect-severity vulnerabilities in the Cursor AI code editor, dubbed DuneSlide, can be triggered by a single malicious prompt to break out…
DHS Confirms Breach of HSIN Sensitive Information-Sharing Platform
An unknown threat actor compromised the Homeland Security Information Network between late May and early June, targeting servers and a SharePoint collaboration…