ZeroHour

Search: “Cyber Command”

4 stories

Commvault security advisory (AV26-895)

Canada's Cyber Centre advisory AV26-895 warns Commvault Cloud builds before 11.36.123/11.40.72/11.44.20/11.46.20 are affected by a Command Center API authentication bypass.

The Canadian Centre for Cyber Security alerted users that Commvault Cloud versions 11.36, 11.40, 11.44 and 11.46, prior to fixed builds 11.36.123, 11.40.72, 11.44.20 and 11.46.20, are affected by issue CV_2026_07_1, a Command Center API authentication bypass. Administrators are encouraged to review the linked vendor advisories and apply the available updates.

Canadian Centre for Cyber Security · 8d agoAdvisory

Dell security advisory (AV26-843)

Canada's Cyber Centre issued advisory AV26-843 covering Dell vulnerabilities requiring updates across Alienware, PowerScale, PowerStore, and other products.

The Canadian Centre for Cyber Security published advisory AV26-843 on August 24, 2026, noting Dell products affected by vulnerabilities as of August 17, 2026. Affected products include Alienware Command Center prior to 6.14.20.0, Dell Command Update prior to 5.7.1, Dell Networking OS10 prior to 10.5.6.14, PowerScale OneFS prior to 14.1, PowerStore OS prior to 5.0.0.2, OpenManage Enterprise prior to 4.7.0, ObjectScale prior to 4.3.0.1, Metro Node prior to 4.6.0.4, and others. Users are directed to apply the vendor's updates.

Canadian Centre for Cyber Security · 23d agoAdvisory

Rockwell Automation ControlFLASH

CISA advisory for CVE-2026-12663 (CVSS 7.3) in Rockwell Automation ControlFLASH <=V15.07: world-writable install directory enables local code execution.

Rockwell Automation reported CVE-2026-12663 in ControlFLASH V15.07 and earlier, where the installer grants write permissions on the installation directory to the Everyone group. An attacker could plant malicious code there and execute it at the logged-in user's privilege level. The issue is local only and not remotely exploitable; no public exploitation has been reported to CISA.

NextGen Healthcare Mirth Connect

CISA warns NextGen Healthcare Mirth Connect <=4.7.1 has SQL injection and XXE flaws enabling credential theft, file writes, and DoS.

CISA released advisory ICSMA-26-253-01 covering three vulnerabilities in NextGen Healthcare Mirth Connect versions 4.7.1 and earlier: SQL injection CVE-2026-82583 (CVSS 8.3), XXE CVE-2026-78224 (CVSS 8.2), and XXE CVE-2026-82578 (CVSS 7.5). Exploitation could expose stored credentials for connected systems, enable arbitrary file writes, and cause denial-of-service conditions. No public exploitation has been reported; the product is deployed worldwide in the Healthcare and Public Health sector.

CISA Advisoriesupdated · 5d agofirst · 6d agoAdvisory 2 sourcesCVE-2026-82583CVE-2026-78224CVE-2026-82578