ZeroHour

Search: “Progress Software”

2 stories in the last 7d

Progress security advisory (AV26-915)

Canadian Cyber Centre advisory AV26-915 warns of a vulnerability in Progress Software Chef Automate prior to 4.13.520.

The Canadian Centre for Cyber Security issued advisory AV26-915 on September 11, 2026, flagging a vulnerability in Progress Software's Chef Automate for versions prior to 4.13.520. The advisory references Progress' Critical Security Bulletin from August 2026 and urges users and administrators to review the linked resources and apply available updates. No exploitation status, CVE identifiers, or technical details are provided.

Canadian Centre for Cyber Security · 5d agoAdvisory

Schneider Electric SCADAPack x70 Products

CISA advisory: Schneider Electric SCADAPack x70 RTUs contain CVE-2026-81861, an insufficiently protected credentials flaw allowing unauthorized access to RTU configuration.

CISA advisory ICSA-26-258-04 discloses CVE-2026-81861 affecting all versions of Schneider Electric SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32 remote terminal units. The CWE-522 insufficiently protected credentials vulnerability could expose authentication information and permit unauthorized access to RTU configuration through the Secure Lock functionality. The flaw carries a CVSS v3.1 base score of 6.5 (medium), and the products are deployed worldwide in critical manufacturing and energy sectors. Abhinav Agarwal reported the vulnerability to CISA.

CISA Advisories · 1d agoAdvisoryCVE-2026-81861