Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
CISA KEV — Microsoft Internet Key Exchange (IKE) Service (CVE-2026-33824) +3 more
Four CVEs affecting Microsoft IKE, SharePoint, Broadcom VMware vCenter, and Apple macOS have been added to CISA’s KEV catalog.
Read more → -
CISA Malcolm
Versions of Malcolm prior to 26.07.0 allow unbounded archive extraction, which can exhaust filesystem resources and cause denial of service.
Read more → -
Siemens Simcenter Nastran
Simcenter Nastran and Simcenter Femap versions earlier than V2606 are vulnerable to CVE-2026-59086.
Read more → -
CISA Adds One Known Exploited Vulnerability to Catalog
CISA added CVE-2025-62593, a Ray Project vulnerability, to its KEV Catalog due to evidence of active exploitation. The advisory references Binding Operational Directive (BOD) 26-04, which requires FCEB agencies to prioritize remediation of high-risk vulnerabilities.
Read more → -
Hitachi Energy APM Edge Product
Hitachi Energy's APM Edge product versions 6.10 and earlier are affected by Dirty Frag vulnerabilities. These vulnerabilities could allow a local, unprivileged user to escalate privileges to root.
Read more → -
AVEVA Enterprise SCADA
Authenticated users with DNA Authority – Operator privilege can modify serialized data, potentially leading to code execution. The issue affects AVEVA Enterprise SCADA versions from 2021 SP2 P5 through 2025.
Read more → -
Haiwell IoT Cloud HMI Gateway
Haiwell IoT Cloud HMI Gateway version 3.40.1.12 is vulnerable to OS command injection via the /setting endpoint.
Read more → -
Siemens Simcenter Femap
Simcenter Femap versions earlier than V2606.0001 are vulnerable to out-of-bounds reads in BMP parsing.
Read more → -
Siemens Solid Edge
Solid Edge versions prior to V225.0.15 and V226.0.7 contain file-parsing bugs that may allow code execution when opening crafted PAR, PSM, or DFT files. Siemens advises updating to the latest releases to remediate the issue.
Read more → -
ANDRITZ HIPASE-250 and 250 SCALA
HIPASE-250 and 250 SCALA versions up to 7.20 store passwords in a reversible format.
Read more → -
Siemens LOGO! Soft Comfort
LOGO! Soft Comfort versions earlier than 9 use a hard-coded AES master key and unsalted password hashes.
Read more → -
Flow Neuroscience FL-100
The Flow Neuroscience FL-100 devices contain a hard-coded credential that bypasses authentication over Bluetooth. Firmware updates are available through the Flow app to remediate the issue.
Read more → -
Siemens Siveillance Video
Siemens Siveillance Video Management Servers are affected by an OS Command Injection vulnerability. The advisory states that this could allow a Remote Code Execution attack.
Read more → -
Johnson Controls Metasys
Metasys versions 12-15 are vulnerable to a persistent cross-site scripting flaw (CVE-2026-34491). The flaw allows a low-privilege user to inject a payload that runs in other users' sessions.
Read more → -
Johnson Controls Inc. Airwall
Airwall versions up to 4.0.4 contain a hard-coded cryptographic key that can decrypt stored configuration data.
Read more → -
Siemens Desigo DXR and PXC Controllers
Malformed BACnet packets can trigger a denial-of-service condition on Siemens Desigo DXR and PXC controllers.
Read more → -
Siemens License Server (SLS)
Versions of Siemens License Server earlier than 5.1 and 5.3 are vulnerable to privilege escalation and path-traversal flaws.
Read more → -
Siemens Parasolid
Parasolid versions earlier than V38.0.235 and V38.1.230 are vulnerable to an out-of-bounds read in X_T file parsing.
Read more → -
Siemens RUGGEDCOM APE1808
Siemens RUGGEDCOM APE1808 devices that include a Fortinet NGFW are listed as affected by cross-site scripting (CVE-2026-23573) and path-traversal (CVE-2026-59839) vulnerabilities.
Read more → -
CISA KEV — Cisco Secure Firewall Adaptive Security Appliance (CVE-2026-20349) +2 more
CISA added CVE-2026-20349 (Cisco ASA/FTD Heap Inspection Vulnerability), CVE-2026-68820 (Microsoft WinSock Use-After-Free Vulnerability), and CVE-2026-72898 (Metabase SQL Injection Vulnerability) to its KEV Catalog.
Read more → -
Pulsetto Vagus Nerve Stimulator
All versions of the Pulsetto Vagus Nerve Stimulator are affected by CVE-2026-18844.
Read more → -
Mira Hormone Monitor, Mira Android App
Mira Hormone Monitor firmware 1.7.1.47 and Mira Android App 4.5.15.4 are vulnerable to eight CVEs, including remote BLE authentication bypass.
Read more → -
#StopRansomware: Gunra Ransomware
Gunra ransomware uses a double-extortion model, encrypting data and threatening to publish exfiltrated files. It is offered as ransomware-as-a-service targeting government and critical-infrastructure organizations.
Read more → -
CPDLC over ATN-B1 Vulnerabilities
All ATN-B1 CPDLC versions are listed as affected. The vulnerabilities enable unauthenticated message injection and denial-of-service conditions.
Read more → -
CISA KEV — Progress LoadMaster (CVE-2026-8037)
CISA added CVE-2026-8037, a command-injection flaw in Progress LoadMaster, to its KEV catalog.
Read more → -
ABB Ability Zenon
ABB Ability Zenon IIoT services with MongoDB 4.2 are listed as affected. The advisory cites CVE-2025-14847, a mismatch in Zlib compressed protocol headers that could allow an unauthenticated client to read uninitialized heap memory.
Read more → -
Johnson Controls Inc. TL280
TL280 firmware versions earlier than 5.63 contain hard-coded credentials. Exploitation could allow access to sensitive information on the device.
Read more → -
Medixant RadiAnt DICOM
RadiAnt DICOM versions up to 2025.2 are vulnerable to a heap out-of-bounds write triggered by crafted DICOM files.
Read more → -
CISA KEV — JetBrains TeamCity (CVE-2026-63077)
CVE-2026-63077 affecting JetBrains TeamCity has been added to CISA’s KEV catalog due to active exploitation.
Read more → -
CISA KEV — IBM Langflow (CVE-2026-9198) +2 more
CISA added three new KEV entries: IBM Langflow code injection (CVE-2026-9198), N-able N-central authentication bypass (CVE-2026-18556), and Apache Tomcat missing encryption (CVE-2026-34486). These are flagged for rapid remediation on publicly exposed assets.
Read more → -
Acrisure KARR BT and DR-100
Devices with firmware older than July 20 2026 use a shared hard-coded Bluetooth key, enabling nearby attackers to issue unauthorized vehicle commands.
Read more → -
Thermo Fisher Applied Biosystems Genetic Analyzers
Thermo Fisher Applied Biosystems data collection software versions up to 4.0.2, 5.0.2, 1.2.5, 1.2.0, and 1.7.3 are listed as vulnerable. The flaw permits modification of .fsa/.hid output files, potentially altering DNA test results.
Read more → -
CISA KEV — N-able N-central (CVE-2026-18577)
CISA added CVE-2026-18577 for N-able N-central to the KEV catalog.
Read more → -
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
CISA is observing an increase in activity targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. These entities have modified passwords to lock out operators and disconnected PLCs by changing their IP addresses.
Read more → -
o6 Automation open62541
Affected open62541 versions include 1.3.0-1.3.17, 1.4.0-1.4.16, 1.5.0-1.5.4, and the master branch. The library runs on Windows and Linux.
Read more → -
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
The advisory reports that certain Rockwell Automation communication modules can be tricked into accepting revoked certificates, which may enable denial-of-service.
Read more → -
MZ Automation lib60870
MZ Automation lib60870 version 2.4.0 is vulnerable to out-of-bounds reads that may cause a device crash.
Read more → -
MZ Automation GmbH libiec61850
Versions of libiec61850 earlier than 1.6.2 are vulnerable to out-of-bounds reads that can cause a denial-of-service.
Read more → -
Johnson Controls OpenBlue Employee
OpenBlue Employee (FMS Employee) versions up to V2025.3.1 permit unrestricted file uploads and stored cross-site scripting.
Read more → -
Watchfire Controller Software
Watchfire Controller Software versions BC550 12.30, BC750 11.33/12.35, BC760 12.38/13.00, and BC760DC 12.39 are listed as affected by CVE-2026-5846. The vulnerability is caused by hard-coded RSA private keys embedded in the firmware.
Read more → -
Toptech Systems RCU II+ and Multiload II+
RCU II+ and Multiload II+ units released before 2025-11-24 expose an unauthenticated debug interface.
Read more → -
MikroTik RouterOS
All MikroTik RouterOS versions with the API enabled are affected by CVE-2026-14227.
Read more → -
Schneider Electric IGSS
The IGSS Definition module (Def.exe) versions up to 18.0.0.26124 are vulnerable to an out-of-bounds write via a crafted CGF file. Schneider Electric provides a fix in version 18.0.0.26125.
Read more → -
Mitsubishi Electric CC-Link IE TSN Communication Protocol
All listed Mitsubishi Electric CC-Link IE TSN controllers, modules, and interface boards are affected regardless of firmware version. Exploitation requires an attacker on the same network segment to send precisely timed packets.
Read more → -
NASA Core Flight System (cFS) Health & Safety (HS) Application
Versions up to 7.0.1 of NASA’s Core Flight System (cFS) Health & Safety (HS) application are vulnerable to a NULL pointer dereference that can cause a denial-of-service.
Read more → -
Open Source Software: Security Principles and Practices
CISA released guidance on securely using, evaluating, and publishing open source software. The guidance covers OSS risk management and vulnerability management.
Read more → -
CISA KEV — Cisco Secure Firewall Management Center (CVE-2026-20316)
CISA added CVE-2026-20316 for Cisco Secure Firewall Management Center to the KEV catalog due to active exploitation.
Read more → -
2026 Minimum Elements for a Software Bill of Materials (SBOM)
The guidance updates the NTIA 2021 minimum elements for SBOMs and incorporates 2025 stakeholder feedback.
Read more → -
igloohome Smart Lock Mobile Application
Version 3.2.3 and earlier of the igloohome Smart Lock Mobile Application for Android contain source code that includes sensitive information, potentially allowing unauthorized access to backend services.
Read more → -
ABB KNX Update Tool
ABB KNX Update Tool versions ≤ 2.0.175 lack firmware integrity checks and can be rendered unusable via physical bus access.
Read more → -
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
The advisory lists dozens of CVEs affecting the GNU/Linux subsystem of firmware V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP.
Read more → -
Siemens Desigo CC
Siemens Desigo CC V7, V8, and V9 versions prior to 9.0.1 are vulnerable to CVE-2025-15467.
Read more → -
Siemens SIMATIC S7-PLCSIM Advanced
The vulnerability allows an unauthenticated attacker on the local network to cause a denial-of-service condition via high-volume multicast traffic. Siemens is preparing fix versions and recommends mitigation steps.
Read more → -
MikroTik RouterOS and Cloud Hosted Router
All MikroTik RouterOS and Cloud Hosted Router versions are affected by CVE-2026-16347, which permits rapid password guessing due to missing rate-limiting.
Read more → -
Siemens Mendix Runtime
Developers may unintentionally grant the anonymous role access to all System.User records. This can expose sensitive user data or enable privilege escalation.
Read more → -
CI Fortify – Advice for isolating vital systems
The guidance advises critical infrastructure organizations to isolate vital operational technology and enabling systems from all other networks during disruptions.
Read more → -
CISA KEV — Fortinet FortiOS (CVE-2025-68686) +1 more
Fortinet FortiOS and Arista VeloCloud Orchestrator on-prem have been added to CISA’s KEV catalog due to active exploitation. The advisory advises rapid remediation for publicly exposed assets.
Read more → -
Panduit IntraVUE
IntraVUE versions up to 3.2.1a14 store passwords in cleartext via the API. The same versions also allow an attacker to act as an active proxy, bypassing OT segmentation.
Read more → -
Johnson Controls C-CURE 9000 and Victor application server
Versions of C-CURE 9000 and Victor up to v2.90_v3.0 (and Victor Web up to v7.1) are vulnerable to unauthenticated remote code execution. The flaw can be triggered from an adjacent network and affect physical-security workstations.
Read more → -
MZ Automation lib60870
Versions of MZ Automation lib60870 up to 2.4.0 are vulnerable to an out-of-bounds read that can cause a denial-of-service. The vendor recommends updating to 2.4.1 or later.
Read more → -
MZ Automation libIEC61850
libIEC61850 versions 1.0.0 through 1.6.1 are affected by stack- and heap-based buffer overflows. The advisory advises updating to the latest build.
Read more → -
Johnson Controls XAAP Android
Versions of the Johnson Controls XAAP Android app prior to 1.53 store data in cleartext on the device.
Read more → -
Weintek cMT3092X
Versions of the cMT3092X firmware earlier than 20210218 and EasyWeb earlier than v2.1.20 are vulnerable to privilege escalation via cookie manipulation.
Read more → -
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
The advisory notes a view-based exploit in Zimbra Collaboration Suite that can exfiltrate recent email and address data when a malicious email is viewed.
Read more → -
CISA KEV — Check Point SmartConsole (CVE-2026-16232) +1 more
Check Point SmartConsole and Microsoft SharePoint have been added to the KEV catalog due to active exploitation.
Read more → -
Rockwell Automation ThinManager
ThinManager versions prior to 13.0.8, 13.1.6, 13.2.5, and 14.0.3 are vulnerable to an authenticated path-traversal flaw.
Read more → -
Siemens Opcenter X
Siemens Opcenter X versions prior to V2604 are vulnerable to an authentication bypass via JWT header manipulation.
Read more → -
Rockwell Automation FactoryTalk Services Platform
FactoryTalk Directory (FTSP) version 6.60 is affected by a JWT signature validation bypass. The flaw enables impersonation of any authorized user on the FTSP server.
Read more → -
Siemens CADRA
CADRA versions earlier than V2511 are vulnerable to multiple high-severity zlib and Foxit flaws.
Read more → -
Rockwell Automation Studio 5000 Logix Designer
Versions V32.00 through V36.00 of Rockwell Automation Studio 5000 Logix Designer are listed as vulnerable. The advisory cites a path-traversal flaw that can lead to arbitrary file writes.
Read more → -
Rockwell Automation 1718-AENTR/1719-AENTR
Rockwell Automation 1718/1719 Ex I/O version 3.011 is vulnerable to a denial-of-service condition caused by a UDP unicast network storm.
Read more → -
Rockwell Automation 1734 POINT I/O
The 1734 POINT I/O module (v3.023) can be forced into a faulted state by crafted CIP messages, causing a denial-of-service.
Read more → -
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
All versions of the Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected by PAN-OS vulnerabilities. The advisory directs customers to apply the workarounds published by Palo Alto Networks.
Read more → -
Siemens IAM Client
The advisory lists specific Siemens product versions vulnerable to an untrusted search path issue that could enable local privilege escalation. Siemens provides updated IAM Client versions for the affected products.
Read more → -
Siemens SIDIS Secured SmartPlug
Versions of Siemens SIDIS Secured SmartPlug earlier than V7.26.0310 are affected by multiple high-severity vulnerabilities.
Read more → -
Tycon Systems TPDIN-Monitor-WEB2
TPDIN-Monitor-WEB2 version 2.3.9 permits authentication bypass by submitting empty credentials.
Read more → -
CISA KEV — DD-WRT (CVE-2021-27137) +3 more
CISA added four actively exploited CVEs—including two WordPress core flaws—to its KEV Catalog.
Read more → -
CISA KEV — Fortinet FortiSandbox (CVE-2026-25089) +2 more
Two FortiSandbox OS command injection flaws and a SharePoint deserialization flaw have been added to the KEV catalog.
Read more → -
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
The advisory reports that crafted CIP Implicit Connection packets can cause a denial-of-service condition on the affected modules. Rockwell Automation provides firmware updates for EN2 and EN3 but none for ENBT.
Read more → -
AutomationDirect Productivity Suite
AutomationDirect Productivity Suite versions up to 4.6.2.2 are listed as affected.
Read more → -
Rockwell Automation Arena
Arena versions up to V17.00.00 are vulnerable to out-of-bounds write flaws that could allow arbitrary code execution.
Read more → -
NASA Core Flight System (cFS) Health & Safety (HS) Application
The HS application can crash on a routine Housekeeping Telemetry request, causing denial of service. Versions prior to 7.0.1 are affected.
Read more → -
Rockwell Automation FactoryTalk DataMosaix
FactoryTalk DataMosaix Private Cloud versions up to 8.02 are vulnerable to a stored cross-site scripting issue. An authenticated attacker could inject scripts that execute when other users view workflow pages.
Read more → -
SALTO ProAccess Space
Versions of SALTO ProAccess Space prior to 6.13 are vulnerable when the tenancy (partition) feature is enabled.
Read more → -
Siemens SICAM 8
Siemens SICAM 8 firmware versions prior to 26.20 (CPCI85) and 26.20.0 (SICORE) are vulnerable to denial-of-service via an authenticated HTTP debug interface.
Read more → -
Rockwell Automation Flex 5000 Adapter
Flex 5000 Adapter version 6.011 is vulnerable to a denial-of-service via crafted CIP packets.
Read more → -
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix controllers are vulnerable to denial-of-service conditions. The vulnerability affects firmware versions up to V35.015 for several model families.
Read more → -
CISA KEV — KNX Association KNX Protocol Connection Authorization (CVE-2023-4346) +1 more
CISA added CVE-2023-4346 (KNX protocol) and CVE-2026-46817 (Oracle E-Business Suite) to the KEV catalog. Both are identified as actively exploited.
Read more → -
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
The guidance is aimed at software manufacturers and online service providers.
Read more → -
CISA KEV — SonicWall SMA1000 Appliances (CVE-2026-15409) +3 more
SonicWall SMA1000 appliances are listed with both SSRF and code injection vulnerabilities in the KEV catalog.
Read more → -
CISA Urges SharePoint Hardening After New Exploitations
Active exploitation of CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 is targeting on-premises SharePoint Server.
Read more → -
ABB Advant Master Online Builder
ABB Advant Master Online Builder versions up to 6.1.1-3 are vulnerable to CVE-2025-13162.
Read more → -
ABB Ability Edgenius
ABB Ability Edgenius versions 3.2.0.0 through 3.2.4.0 are vulnerable to CVE-2026-31431. An update to version 3.2.4.1 resolves the issue.
Read more → -
Rockwell Automation 1715-AENTR EtherNet/IP Adapter
Versions up to 3.003 of the Rockwell Automation 1715-AENTR EtherNet/IP Adapter are vulnerable. The device exposes an unauthenticated debug port.
Read more → -
ABB T-MAC Plus
ABB T-MAC Plus version 4.0-24 is affected; ABB provides an update to version 4.0-25 that resolves the vulnerabilities.
Read more → -
CISA KEV — Cisco IOS (CVE-2008-4128)
CVE-2008-4128, a cross-site request forgery flaw in Cisco IOS, has been added to CISA’s KEV Catalog. The advisory urges rapid remediation on publicly exposed assets that grant total control.
Read more → -
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
Russian FSB Center 16 actors are exploiting poorly configured and vulnerable networking devices worldwide.
Read more → -
CISA KEV — iCagenda (CVE-2026-48939) +1 more
CISA added CVE-2026-48939 and CVE-2026-56291 to its KEV Catalog. These vulnerabilities involve unrestricted file uploads with potentially harmful file types.
Read more → -
Schneider Electric Easergy MiCOM Px40 Series
The advisory states that hard-coded credentials in the SNMP protocol could allow unauthorized access to basic device identification.
Read more → -
OpenPLC v3
An authenticated attacker can write arbitrary files via a legacy web UI upload flaw, potentially leading to native code execution through the default compilation process.
Read more →
Page 1 of 4 · 301 advisories