Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
CISA KEV — Microsoft Internet Key Exchange (IKE) Service (CVE-2026-33824) +3 more
Four CVEs affecting Microsoft IKE, SharePoint, Broadcom VMware vCenter, and Apple macOS have been added to CISA’s KEV catalog.
Read more → -
CISA Malcolm
Versions of Malcolm prior to 26.07.0 allow unbounded archive extraction, which can exhaust filesystem resources and cause denial of service.
Read more → -
Siemens Simcenter Nastran
Simcenter Nastran and Simcenter Femap versions earlier than V2606 are vulnerable to CVE-2026-59086.
Read more → -
CISA Adds One Known Exploited Vulnerability to Catalog
CISA added CVE-2025-62593, a Ray Project vulnerability, to its KEV Catalog due to evidence of active exploitation. The advisory references Binding Operational Directive (BOD) 26-04, which requires FCEB agencies to prioritize remediation of high-risk vulnerabilities.
Read more → -
Hitachi Energy APM Edge Product
Hitachi Energy's APM Edge product versions 6.10 and earlier are affected by Dirty Frag vulnerabilities. These vulnerabilities could allow a local, unprivileged user to escalate privileges to root.
Read more → -
AVEVA Enterprise SCADA
Authenticated users with DNA Authority – Operator privilege can modify serialized data, potentially leading to code execution. The issue affects AVEVA Enterprise SCADA versions from 2021 SP2 P5 through 2025.
Read more → -
Haiwell IoT Cloud HMI Gateway
Haiwell IoT Cloud HMI Gateway version 3.40.1.12 is vulnerable to OS command injection via the /setting endpoint.
Read more → -
Siemens Simcenter Femap
Simcenter Femap versions earlier than V2606.0001 are vulnerable to out-of-bounds reads in BMP parsing.
Read more → -
Siemens Solid Edge
Solid Edge versions prior to V225.0.15 and V226.0.7 contain file-parsing bugs that may allow code execution when opening crafted PAR, PSM, or DFT files. Siemens advises updating to the latest releases to remediate the issue.
Read more → -
ANDRITZ HIPASE-250 and 250 SCALA
HIPASE-250 and 250 SCALA versions up to 7.20 store passwords in a reversible format.
Read more → -
Siemens LOGO! Soft Comfort
LOGO! Soft Comfort versions earlier than 9 use a hard-coded AES master key and unsalted password hashes.
Read more → -
Flow Neuroscience FL-100
The Flow Neuroscience FL-100 devices contain a hard-coded credential that bypasses authentication over Bluetooth. Firmware updates are available through the Flow app to remediate the issue.
Read more → -
Siemens Siveillance Video
Siemens Siveillance Video Management Servers are affected by an OS Command Injection vulnerability. The advisory states that this could allow a Remote Code Execution attack.
Read more → -
Johnson Controls Metasys
Metasys versions 12-15 are vulnerable to a persistent cross-site scripting flaw (CVE-2026-34491). The flaw allows a low-privilege user to inject a payload that runs in other users' sessions.
Read more → -
Johnson Controls Inc. Airwall
Airwall versions up to 4.0.4 contain a hard-coded cryptographic key that can decrypt stored configuration data.
Read more → -
Siemens Desigo DXR and PXC Controllers
Malformed BACnet packets can trigger a denial-of-service condition on Siemens Desigo DXR and PXC controllers.
Read more → -
Siemens License Server (SLS)
Versions of Siemens License Server earlier than 5.1 and 5.3 are vulnerable to privilege escalation and path-traversal flaws.
Read more → -
Siemens Parasolid
Parasolid versions earlier than V38.0.235 and V38.1.230 are vulnerable to an out-of-bounds read in X_T file parsing.
Read more → -
ZDI-26-568: Linux Kernel Net Scheduler Race Condition Local Privilege Escalation Vulnerability
A race condition in the Linux kernel net scheduler can be leveraged for local privilege escalation. CVSS is rated 7.5.
Read more → -
ZDI-26-569: Linux Kernel Net Scheduler True Link Equalizer Race Condition Local Privilege Escalation Vulnerability
A race condition in the Linux kernel’s Net Scheduler True Link Equalizer can be used for local privilege escalation.
Read more → -
ZDI-26-570: Linux Kernel IGMP Subsystem Race Condition Local Privilege Escalation Vulnerability
The advisory identifies a race condition in the Linux kernel's IGMP subsystem that can be used for local privilege escalation.
Read more → -
ZDI-26-571: Linux Kernel Net Scheduler Packet Classifier API Use-After-Free Local Privilege Escalation Vulnerability
The flaw is a use-after-free in the Linux kernel’s Net Scheduler packet classifier API. It enables local privilege escalation after low-privilege code execution.
Read more → -
ZDI-26-572: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability
The advisory notes a race condition in the Linux kernel XFRM subsystem that can be leveraged for local privilege escalation.
Read more → -
ZDI-26-573: Linux Kernel KSMBD Response Header Out-Of-Bounds Read Information Disclosure Vulnerability
An out-of-bounds read in ksmbd response header handling can disclose information without authentication.
Read more → -
ZDI-26-574: Linux Kernel Net Scheduler Connection Tracking Race Condition Local Privilege Escalation Vulnerability
The issue is a race condition in the Linux kernel net scheduler connection tracking code. It enables local privilege escalation.
Read more → -
ZDI-26-575: Linux Kernel Net Scheduler Packet Classifier API Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
The vulnerability is a local TOCTOU privilege escalation in the Linux kernel's Net Scheduler packet classifier API.
Read more → -
ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability
The advisory notes a race condition in the Linux kernel's XFRM subsystem that can be exploited for local privilege escalation.
Read more → -
ZDI-26-577: Trend Micro VPN OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Trend Micro VPN contains an uncontrolled OpenSSL search path element that enables local privilege escalation.
Read more → -
ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability
The advisory notes an integer underflow in the NGINX HTTP Dav module’s alias directive.
Read more → -
ZDI-26-579: Cisco Identity Services Engine zipFiles Directory Traversal Remote Code Execution Vulnerability
Exploitation requires valid authentication and leverages a directory traversal in the zipFiles component.
Read more → -
ZDI-26-580: Cisco Identity Services Engine Missing Authentication for Critical Function Information Disclosure Vulnerability
Authentication is not required to retrieve sensitive information from Cisco Identity Services Engine.
Read more → -
ZDI-26-581: Cisco Identity Services Engine invokeScript Command Injection Remote Code Execution Vulnerability
Remote code execution is possible via an authenticated invokeScript command injection.
Read more → -
ZDI-26-582: Cisco Identity Services Engine PatchUpdateListener Directory Traversal Information Disclosure Vulnerability
Remote authenticated attackers can exploit a directory traversal in PatchUpdateListener to disclose sensitive information.
Read more → -
ZDI-26-583: Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability
Clam AntiVirus 7z archive parsing contains an integer overflow that can be remotely triggered.
Read more → -
ZDI-26-584: dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability
dnsmasq can enter an infinite loop while processing DNSSEC NSEC/NSEC3 type bitmap, causing a denial of service.
Read more → -
ZDI-26-564: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
Remote code execution is possible via deserialization of untrusted data in Transformers4Rec's load_model_trainer_states_from_checkpoint function.
Read more → -
ZDI-26-565: Gen Digital CCleaner Link Following Local Privilege Escalation Vulnerability
Local privilege escalation in Gen Digital CCleaner (CVE-2026-12410) with CVSS 7.8.
Read more → -
ZDI-26-566: BlackBerry QNX KEV File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious file or visit a malicious web page.
Read more → -
ZDI-26-567: Norton Utilities Ultimate NortonUtilitiesSvc Link Following Local Privilege Escalation Vulnerability
The vulnerability enables local privilege escalation via the NortonUtilitiesSvc component.
Read more → -
Siemens RUGGEDCOM APE1808
Siemens RUGGEDCOM APE1808 devices that include a Fortinet NGFW are listed as affected by cross-site scripting (CVE-2026-23573) and path-traversal (CVE-2026-59839) vulnerabilities.
Read more → -
ZDI-26-557: (Pwn2Own) Amazon Smart Plug Insecure Fallback Information Disclosure Vulnerability
Unauthenticated network-adjacent attackers can retrieve sensitive information from Amazon Smart Plug devices.
Read more → -
ZDI-26-558: (Pwn2Own) Amazon Smart Plug OTA Update Process Improper Certificate Validation Vulnerability
Network-adjacent attackers can bypass certificate validation for OTA updates on Amazon Smart Plug.
Read more → -
ZDI-26-559: (Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability
Unauthenticated attackers on the same network can trigger an out-of-bounds write via the OTA update process.
Read more → -
ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
The vulnerability enables remote code execution after an attacker reaches the localhost interface.
Read more → -
ZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
The Home Assistant Green device is vulnerable to command injection. This allows for remote code execution.
Read more → -
ZDI-26-562: (Pwn2Own) Home Assistant Green mDNS Server-Side Request Forgery Vulnerability
Home Assistant Green's mDNS server-side request forgery vulnerability allows network-adjacent attackers to initiate arbitrary server-side requests. Authentication is not required.
Read more → -
ZDI-26-563: (Pwn2Own) Home Assistant Green Simple Service Discovery Protocol Server-Side Request Forgery Vulnerability
Unauthenticated network-adjacent attackers can trigger arbitrary server-side requests via Home Assistant Green's Simple Service Discovery Protocol server.
Read more → -
CISA KEV — Cisco Secure Firewall Adaptive Security Appliance (CVE-2026-20349) +2 more
CISA added CVE-2026-20349 (Cisco ASA/FTD Heap Inspection Vulnerability), CVE-2026-68820 (Microsoft WinSock Use-After-Free Vulnerability), and CVE-2026-72898 (Metabase SQL Injection Vulnerability) to its KEV Catalog.
Read more → -
Pulsetto Vagus Nerve Stimulator
All versions of the Pulsetto Vagus Nerve Stimulator are affected by CVE-2026-18844.
Read more → -
Mira Hormone Monitor, Mira Android App
Mira Hormone Monitor firmware 1.7.1.47 and Mira Android App 4.5.15.4 are vulnerable to eight CVEs, including remote BLE authentication bypass.
Read more → -
ZDI-26-542: Microsoft Windows UMPDDrvBitBlt Improper Object Management Local Privilege Escalation Vulnerability
Local attackers can exploit an improper object management flaw in UMPDDrvBitBlt to gain higher privileges.
Read more → -
ZDI-26-543: Microsoft Windows ICC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Exploitation requires interaction with the Mscms.dll color management library.
Read more → -
ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability
A use-after-free in Windows Deployment Services can be triggered without authentication by a network-adjacent attacker.
Read more → -
ZDI-26-545: Flowise CSV_Agent customReadCSV Code Injection Remote Code Execution Vulnerability
Remote code execution is possible on Flowise installations, but exploitation requires authentication.
Read more → -
ZDI-26-546: Flowise Airtable_Agent Code Injection Remote Code Execution Vulnerability
Unauthenticated remote code execution via code injection in Flowise Airtable_Agent.
Read more → -
ZDI-26-547: OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious OPJU file or visit a crafted web page.
Read more → -
ZDI-26-548: OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
OriginLab OriginPro can be compromised via a crafted OPJ file that triggers an out-of-bounds write.
Read more → -
ZDI-26-549: OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
OriginPro's OGG file parser contains an out-of-bounds write that can be triggered by a crafted OGG file.
Read more → -
ZDI-26-550: OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability
OriginPro's OGW file parser can be triggered remotely via a crafted file, causing memory corruption.
Read more → -
ZDI-26-551: OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability
OriginLab OriginPro can be remotely compromised via a crafted OGG file, but exploitation requires the victim to open the file or visit a malicious page.
Read more → -
ZDI-26-552: OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
A crafted OPJ file can trigger an out-of-bounds write in Origin Viewer, enabling remote code execution.
Read more → -
ZDI-26-553: OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability
Origin Viewer can execute arbitrary code when parsing a malicious OGW file opened by a user. Exploitation requires the victim to visit a malicious page or open a crafted file.
Read more → -
ZDI-26-554: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
Local privilege escalation in Parallels RAS Client requires prior low-privileged code execution.
Read more → -
ZDI-26-555: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
The Parallels RAS Client RDP Backend Service has a vulnerability allowing local attackers to escalate privileges. The ZDI has assigned the CVE-2026-18262.
Read more → -
ZDI-26-556: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation in the Parallels RAS Client RDP backend service.
Read more → -
ZDI-26-527: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability
Exploitation requires a prior low-privileged foothold on a Wazuh worker node. The flaw is a deserialization of untrusted data in the Cluster DAPI protocol.
Read more → -
ZDI-26-528: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability
Exploitation requires prior low-privileged code execution on a Wazuh worker node. The flaw is a deserialization of untrusted data in the Cluster DAPI protocol.
Read more → -
ZDI-26-529: Samsung Galaxy S25 TIFF File Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Heap-based buffer overflow in TIFF file processing on Samsung Galaxy S25 enables remote code execution.
Read more → -
ZDI-26-530: SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability
The vulnerability is a local SNMP command injection that enables privilege escalation.
Read more → -
ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability
The vulnerability enables local privilege escalation on SonicWall GMS Virtual Appliance.
Read more → -
ZDI-26-532: SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerability
Local command injection in the updateNetIf function can be leveraged for privilege escalation on SonicWall Email Security.
Read more → -
ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerability
Authentication can be bypassed without credentials on Cisco Secure Firewall Management Center login.cgi.
Read more → -
ZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability
Remote attackers can bypass authentication on Microsoft Exchange without credentials.
Read more → -
ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability
Authentication can be bypassed to achieve remote code execution on Microsoft Exchange.
Read more → -
ZDI-26-536: (Pwn2Own) Microsoft Windows http.sys Integer Overflow Local Privilege Escalation Vulnerability
An integer overflow in the Windows http.sys driver enables local privilege escalation.
Read more → -
ZDI-26-537: (Pwn2Own) Microsoft Windows storport Integer Overflow Local Privilege Escalation Vulnerability
The advisory reports an integer overflow in the Windows storport driver that enables local privilege escalation.
Read more → -
ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability
Remote attackers can bypass authentication to gain higher privileges on Microsoft Exchange.
Read more → -
ZDI-26-539: (Pwn2Own) Microsoft Windows ipt.sys Incorrect Permission Assignment Local Privilege Escalation Vulnerability
The advisory notes that ipt.sys has incorrect permission assignment enabling local privilege escalation.
Read more → -
ZDI-26-540: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Information Disclosure Vulnerability
The win32kfull subsystem contains a use-after-free that can disclose sensitive data after low-privilege code execution.
Read more → -
ZDI-26-541: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Local Privilege Escalation Vulnerability
The advisory reports a use-after-free flaw in win32kfull that enables local privilege escalation.
Read more → -
#StopRansomware: Gunra Ransomware
Gunra ransomware uses a double-extortion model, encrypting data and threatening to publish exfiltrated files. It is offered as ransomware-as-a-service targeting government and critical-infrastructure organizations.
Read more → -
CPDLC over ATN-B1 Vulnerabilities
All ATN-B1 CPDLC versions are listed as affected. The vulnerabilities enable unauthenticated message injection and denial-of-service conditions.
Read more → -
CISA KEV — Progress LoadMaster (CVE-2026-8037)
CISA added CVE-2026-8037, a command-injection flaw in Progress LoadMaster, to its KEV catalog.
Read more → -
ABB Ability Zenon
ABB Ability Zenon IIoT services with MongoDB 4.2 are listed as affected. The advisory cites CVE-2025-14847, a mismatch in Zlib compressed protocol headers that could allow an unauthenticated client to read uninitialized heap memory.
Read more → -
Johnson Controls Inc. TL280
TL280 firmware versions earlier than 5.63 contain hard-coded credentials. Exploitation could allow access to sensitive information on the device.
Read more → -
Medixant RadiAnt DICOM
RadiAnt DICOM versions up to 2025.2 are vulnerable to a heap out-of-bounds write triggered by crafted DICOM files.
Read more → -
CISA KEV — JetBrains TeamCity (CVE-2026-63077)
CVE-2026-63077 affecting JetBrains TeamCity has been added to CISA’s KEV catalog due to active exploitation.
Read more → -
ZDI-26-524: (0Day) PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability
The Q80 XCB daemon accepts unauthenticated requests that can read and alter configuration data.
Read more → -
ZDI-26-525: (0Day) PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability
Unauthenticated attackers can achieve remote code execution on PAX Technology Q80 via crafted AIP files.
Read more → -
ZDI-26-526: (0Day) PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability
Unauthenticated attackers can bypass the Q80 Application Installer’s signature verification to execute code remotely.
Read more → -
CISA KEV — IBM Langflow (CVE-2026-9198) +2 more
CISA added three new KEV entries: IBM Langflow code injection (CVE-2026-9198), N-able N-central authentication bypass (CVE-2026-18556), and Apache Tomcat missing encryption (CVE-2026-34486). These are flagged for rapid remediation on publicly exposed assets.
Read more → -
Acrisure KARR BT and DR-100
Devices with firmware older than July 20 2026 use a shared hard-coded Bluetooth key, enabling nearby attackers to issue unauthorized vehicle commands.
Read more → -
Thermo Fisher Applied Biosystems Genetic Analyzers
Thermo Fisher Applied Biosystems data collection software versions up to 4.0.2, 5.0.2, 1.2.5, 1.2.0, and 1.7.3 are listed as vulnerable. The flaw permits modification of .fsa/.hid output files, potentially altering DNA test results.
Read more → -
CISA KEV — N-able N-central (CVE-2026-18577)
CISA added CVE-2026-18577 for N-able N-central to the KEV catalog.
Read more → -
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
CISA is observing an increase in activity targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. These entities have modified passwords to lock out operators and disconnected PLCs by changing their IP addresses.
Read more → -
o6 Automation open62541
Affected open62541 versions include 1.3.0-1.3.17, 1.4.0-1.4.16, 1.5.0-1.5.4, and the master branch. The library runs on Windows and Linux.
Read more → -
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
The advisory reports that certain Rockwell Automation communication modules can be tricked into accepting revoked certificates, which may enable denial-of-service.
Read more → -
MZ Automation lib60870
MZ Automation lib60870 version 2.4.0 is vulnerable to out-of-bounds reads that may cause a device crash.
Read more → -
MZ Automation GmbH libiec61850
Versions of libiec61850 earlier than 1.6.2 are vulnerable to out-of-bounds reads that can cause a denial-of-service.
Read more → -
Johnson Controls OpenBlue Employee
OpenBlue Employee (FMS Employee) versions up to V2025.3.1 permit unrestricted file uploads and stored cross-site scripting.
Read more →
Page 1 of 9 · 805 advisories