ZeroHour

Search: “cwe”

7 stories in the last 3d

Hitachi Energy FACTS Control Platform (FCP)

CISA republished Hitachi Energy's advisory on five flaws, including two critical CVSS 9.9 issues, in the FACTS Control Platform GWS component for grid systems.

CISA republished Hitachi Energy's advisory for the FACTS Control Platform (FCP) with the GWS component, versions 3.4.0 through 4.1.1, deployed in energy infrastructure such as SVC Light STATCOMs, series capacitors, and synchronous condensers. Five issues are covered: CVE-2024-4872 authenticated query injection (CVSS 9.9), CVE-2024-3980 path traversal (9.9), CVE-2024-3982 capture-replay authentication bypass (8.2), CVE-2024-7940 unauthenticated exposed local service (8.3), and CVE-2024-7941 open redirect. Deployments from 2020 onwards that include the GWS component are likely affected, and vendor mitigation guidance is provided.

Bransys ELD

CISA reports Bransys ELD apps ship hardcoded MQTT and FTP credentials plus cleartext transport, exposing real-time telemetry for connected fleet devices.

CISA's advisory covers three Bransys ELD mobile app flaws: CVE-2026-86520 hardcoded MQTT credentials (CVSS 7.5), CVE-2026-86689 cleartext transmission of sensitive information, and CVE-2026-77960 hardcoded FTP credentials. Exploitation could allow unauthorized reading of real-time telemetry data from every active device connected to affected brokers across a subset of carriers. Android versions below 11.00.00 and iOS versions below 1.1.54 are affected; no public exploitation has been reported to CISA.

AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460

Canada's Cyber Centre alerts on three actively exploited Cisco ISE/ISE-PIC vulnerabilities enabling unauthenticated administrative access and data tampering.

Canada's Cyber Centre issued alert AL26-021 for three flaws in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC): CVE-2026-20192 (improper access control, CWE-284), CVE-2026-76423 (authentication bypass by spoofing, CWE-290), and CVE-2026-76460 (incorrect use of privileged APIs, CWE-648). Successful exploitation could let unauthenticated attackers bypass authentication, gain administrative access, and read or modify ISE configuration and identity data. Cisco confirmed active exploitation of CVE-2026-76460, which CISA added to its KEV catalog on September 16, 2026. Fixes ship in ISE 3.1–3.5 patches, and defenders are urged to prioritize that CVE, restrict management interfaces, and hunt for IoCs.

Canadian Centre for Cyber Securityupdated · 17h agofirst · 20h agoAdvisory in the wild 26 sourcesCVE-2026-20192CVE-2026-76423CVE-2026-76460

Schneider Electric Modicon M340 Controller and Communication Modules

CISA warns CVE-2025-6625 lets unauthenticated attackers crash Schneider Electric Modicon M340 controllers and communication modules via a crafted FTP command.

Schneider Electric advisory SEVD-2025-224-05, republished by CISA, describes CVE-2025-6625 (CWE-20 improper input validation) in Modicon M340 controllers and X80 Ethernet, M580 Global Data, and Modbus/TCP modules. A crafted FTP command sent to an affected device causes denial of service, with CVSS v3.1 base score 7.5. Fixes are available, including firmware SV3.70 for the Modicon M340 controller.

Cisco Nexus Dashboard Software Security Hardening Release: September 2026

Cisco released Nexus Dashboard hardening updates for multiple internally discovered vulnerabilities, grouped by CWE and not known to be exploited.

Cisco's Nexus Dashboard engineering team conducted an internal security review that found multiple vulnerabilities, addressed via software hardening releases. The issues were discovered during internal testing and are not known to be actively exploited. Cisco grouped the issues by CWE class and assigned a single CVE ID per issue before releasing fixes.

Cisco Security Advisoriesupdated · 1d agofirst · 1d agoAdvisory 2 sources

ABB Ability Edgenius

CISA's ABB advisory covers CVE-2026-31431, a public Linux kernel flaw letting local users or compromised containers gain root on Ability Edgenius gateways.

ABB confirmed that CVE-2026-31431 (Copy Fail), a Linux kernel flaw in the algif_aead cryptographic interface (CWE-669), affects Ability Edgenius versions 3.2.0.0 to below 3.2.4.1 on bE100 gateways. A locally authenticated user or compromised container workload can gain root privileges, enabling arbitrary code execution or denial of service on the node. CVSS v3.1 score is 7.8, and the flaw impacts kernels shipped in most major Linux distributions since 2017. A fix is available and ABB reported no exploitation of Edgenius when the advisory was issued.

CISA Advisoriesupdated · 1h agofirst · 1d agoAdvisory 2 sourcesCVE-2026-31431

Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

CISA updated its CC-Link IE TSN advisory: segment-attached attackers can tamper with Mitsubishi Electric control data and trigger denial of service conditions.

CISA updated its advisory (ICSA-26-211-07 Update A) on a CWE-924 improper enforcement of message integrity flaw in the Mitsubishi Electric CC-Link IE TSN communication protocol. An attacker on the same network segment can send specially crafted packets under specific timing conditions to tamper with control input and output values, causing incorrect operation or denial of service in affected products. Affected products span numerous models, including MELSEC MX controllers, RJ71GN11 modules, motion modules (RD78G/LD78G), FX5 units, and NZ2GN block-type remote modules.

CISA Advisories · 1d agoAdvisory 2 sources