ZeroHour

Search: “python”

4 stories in the last 30d

USN-8744-1: Python vulnerabilities

Ubuntu issued USN-8744-1 fixing CVE-2026-3644, a Python http.cookies content-injection flaw, plus a pyexpat recursion DoS across six Ubuntu LTS releases.

Ubuntu published security notice USN-8744-1 addressing two Python vulnerabilities affecting Ubuntu 14.04 LTS through 24.04 LTS. CVE-2026-3644 concerns incorrect handling of control characters in the http.cookies module, which could allow an attacker to inject arbitrary content. The second issue involves unbounded recursion in the Expat XML parser reached via the pyexpat module, which could crash Python and cause a denial of service. Updated packages are available; no exploitation in the wild is reported.

Ubuntu Security Noticesupdated · 4d agofirst · 5d agoAdvisory 13 sourcesCVE-2026-36441

USN-8765-1: python-sql vulnerability

Ubuntu patches python-sql SQL injection flaw where values passed to unary operators are incorrectly escaped.

Ubuntu Security Notice USN-8765-1 fixes a vulnerability in python-sql discovered by Cedric Krier. The library incorrectly escaped values passed to unary operators, allowing an attacker to potentially perform SQL injection attacks against applications using the library.

Ubuntu Security Notices · 13h agoAdvisory

CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production

CISA, NSA, FBI and other agencies warn of active targeting of internet-exposed Siemens S7 PLCs and urge patching, exposure removal and hardening.

Joint advisory AA26-231A from the NSA, CISA, FBI, Department of Energy and EPA warns that actors are actively targeting Siemens S7 PLCs using internet scanning, AI-assisted scripts and libraries such as Snap7 and python-snap7 over S7comm on TCP port 102. The advisory covers S7-200 through S7-1500 series controllers and recommends patching, removing internet exposure, access controls, monitoring and disabling unneeded services. Siemens states no new S7 vulnerabilities are involved, only misconfigurations addressed in existing ProductCERT guidance SSB-104599. The article details how to apply each measure without breaking production dependencies such as remote I/O, HMI links and diagnostics.

CSO Online · 7d agoAdvisory in the wild

Dell security advisory (AV26-886)

Canada's Cyber Centre flags September 2026 Dell vulnerabilities across iDRAC9/iDRAC10, OpenManage, PowerEdge, Avamar, NetWorker VE, PowerProtect, IDPA and PowerScale OneFS.

Canadian Centre for Cyber Security advisory AV26-886 lists Dell vulnerabilities across iDRAC9, iDRAC10, OpenManage Network Integration, PowerEdge servers, the OpenManage Python SDK, Avamar, NetWorker Virtual Edition, PowerProtect DP Series, IDPA and PowerScale OneFS. Fixed versions include iDRAC9 7.30.10.50, iDRAC10 1.30.30.50 and OpenManage Network Integration 3.10. No CVE identifiers or exploitation status are provided; administrators are urged to apply the vendor updates.

Canadian Centre for Cyber Security · 7d agoAdvisory