ZeroHour

Search: “mobile”

90 items

AMD security advisory (AV26-879)

Canadian Centre for Cyber Security advisory AV26-879 lists vulnerabilities across AMD EPYC, Ryzen, Threadripper, Instinct, and embedded processors, urging updates.

The September 3, 2026 advisory states AMD is affected by processor vulnerabilities as of September 2, 2026, spanning 2nd-4th Gen EPYC, Ryzen 3000-7045 series, Athlon, Threadripper, Radeon PRO V620, Instinct MI300A, and embedded product lines. It specifies required microcode package versions for each affected family and encourages users and administrators to review AMD's links and apply updates as they become available.

Canadian Centre for Cyber Security · 14d agoAdvisory

Samsung mobile security advisory (AV26-919)

Canadian Cyber Centre relays Samsung's September 2026 mobile security update (SMR-SEP-2026) fixing multiple vulnerabilities; users urged to apply patches.

The Canadian Centre for Cyber Security issued advisory AV26-919 on September 14, 2026, relaying Samsung's September 8, 2026 security update for Samsung mobile devices. The update covers versions prior to SMR-SEP-2026 and resolves multiple identified vulnerabilities. Users and administrators are encouraged to review the Samsung bulletin and apply the necessary update.

Canadian Centre for Cyber Security · 3d agoAdvisory

Apple Releases iOS 27 Security Update to Fix Over 120 Vulnerabilities

Apple released iOS 27 and iPadOS 27 patching roughly 126 vulnerabilities across kernel, WebKit, sandboxing, and authentication components; no active exploitation reported.

Apple released iOS 27 and iPadOS 27 on September 14, 2026, fixing approximately 126 vulnerabilities across more than 90 components, including the kernel, WebKit, AppleKeyStore, Sandbox, and TCC. Flaws include memory corruption, information disclosure, denial-of-service, logic errors, sandbox escapes enabling root privileges, and a Bluetooth issue permitting remote code execution in specific circumstances. Apple also shipped iOS 26.7 and iPadOS 26.7 with over 80 fixes for users delaying the major upgrade, including 75 vulnerabilities shared with iOS 27. No vulnerabilities were reported as actively exploited at release time.

GBHackers · 2d agoAdvisory

Ivanti security advisory (AV26-897)

Canada's Cyber Centre relayed Ivanti's September 2026 security updates for Endpoint Manager Mobile, Neurons for ITSM, and Sentry, urging administrators to patch.

The Canadian Centre for Cyber Security forwarded Ivanti's September 2026 security updates covering Endpoint Manager Mobile, Neurons for ITSM (cloud/SaaS and on-prem), and Sentry. Affected releases include Endpoint Manager Mobile prior to 12.10.0.0, Sentry prior to R10.8.2, and Neurons for ITSM on-prem prior to 2026.2. The advisory references CVE-2026-18851 for Endpoint Manager Mobile and CVE-2026-83527 for Sentry, plus multiple CVEs in Neurons for ITSM. No exploitation is described in the advisory text.

Schneider Electric Modicon M340 Controller and Communication Modules

CISA warns CVE-2025-6625 lets unauthenticated attackers crash Schneider Electric Modicon M340 controllers and communication modules via a crafted FTP command.

Schneider Electric advisory SEVD-2025-224-05, republished by CISA, describes CVE-2025-6625 (CWE-20 improper input validation) in Modicon M340 controllers and X80 Ethernet, M580 Global Data, and Modbus/TCP modules. A crafted FTP command sent to an affected device causes denial of service, with CVSS v3.1 base score 7.5. Fixes are available, including firmware SV3.70 for the Modicon M340 controller.

Schneider Electric NetBotz 5 750/755

CISA and Schneider Electric issued an advisory for NetBotz 5 750/755 covering OS command injection and Hibernate SQL injection flaws in versions 5.5.2 and prior.

CISA published ICSA-26-260-05 for two flaws in Schneider Electric NetBotz 5 750/755 environmental monitors running versions 5.5.2 and prior. CVE-2026-13336 (CWE-78, CVSS 6.4) allows Linux command execution when a maliciously modified backup is restored, and CVE-2026-13337 (CWE-564, CVSS 4.6) allows HQL injection into the NetBotz database via the web interface. Successful exploitation could enable code execution, device manipulation, and unauthorized data access on the local network.

Schneider Electric PowerChute Serial Shutdown

CISA and Schneider Electric warn that PowerChute Serial Shutdown 1.5 and prior lack brute-force protection, allowing unauthorized account access via unlimited authentication attempts.

CVE-2026-13348 (CWE-307, CVSS 5.3) in Schneider Electric PowerChute Serial Shutdown versions 1.5 and prior lets attackers perform an arbitrary number of authentication attempts when redirect handling is disabled, gaining unauthorized access to user accounts. The UPS management software is deployed across commercial facilities, critical manufacturing, energy, and IT sectors worldwide. CISA advisory ICSA-26-260-07 recommends network isolation, VPN-protected remote access, and applying the vendor fix.

Schneider Electric SCADAPack x70 Products

CISA advisory: Schneider Electric SCADAPack x70 RTUs contain CVE-2026-81861, an insufficiently protected credentials flaw allowing unauthorized access to RTU configuration.

CISA advisory ICSA-26-258-04 discloses CVE-2026-81861 affecting all versions of Schneider Electric SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32 remote terminal units. The CWE-522 insufficiently protected credentials vulnerability could expose authentication information and permit unauthorized access to RTU configuration through the Secure Lock functionality. The flaw carries a CVSS v3.1 base score of 6.5 (medium), and the products are deployed worldwide in critical manufacturing and energy sectors. Abhinav Agarwal reported the vulnerability to CISA.

CISA Advisories · 3d agoAdvisoryCVE-2026-81861

Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

CISA updated ICSA-26-169-07: CVE-2026-4827 (CVSS 8.3) insufficient entropy enables session hijacking across dozens of Schneider Electric grid products; fixes available.

CISA republished advisory ICSA-26-169-07 (Update A) for CVE-2026-4827, CWE-331 insufficient entropy in session management, scored CVSS 8.3. Affected lines include Easergy MiCOM relays and C5, EcoStruxure Power Automation (EPAS-GTW, EPAS-UI, iPMFLS), EcoStruxure Power Operation, PowerLogic P5/P7/T300/T500, and Saitel DP/T150 RTUs, with dozens of fixed versions listed. Successful exploitation could enable session hijacking and unauthorized operations on systems in energy, chemical, critical manufacturing, and water sectors. Fixes are available; no exploitation is reported.

CISA Advisories · 15d agoAdvisoryCVE-2026-4827