ZeroHour

Search: “web server”

12 stories

Rockwell Automation ArmorStart LT

CISA flags two flaws (CVE-2026-19471, CVE-2026-19472) in Rockwell Automation ArmorStart LT <=v2.001: stored XSS and web server denial-of-service.

Rockwell Automation reported two issues in the embedded web server of ArmorStart LT v2.001 and earlier. CVE-2026-19471 involves multiple stored cross-site scripting flaws (CVSS 7.3) where unsanitized input is stored server-side and executes in other users' browsers. CVE-2026-19472 is a denial-of-service issue (CVSS 7.5) triggered by a crafted HTTP PUT request that exhausts web server resources. No public exploitation has been reported to CISA.

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

Cisco expanded an SSL VPN denial-of-service advisory to cover all ASA and FTD software platforms; unauthenticated attackers can exhaust device memory.

A vulnerability in the VPN and management web servers of Cisco ASA Software and Cisco Secure FTD Software allows an unauthenticated remote attacker to exhaust system memory or buffer blocks, causing a denial of service. Originally scoped to the ASAv and FTDv virtual appliances, Cisco updated the advisory on September 16, 2026 to cover all ASA and FTD platforms.

NVIDIA security advisory (AV26-900)

Canada's Cyber Centre flags NVIDIA Triton Inference Server versions through 26.03 and 26.06 as vulnerable, urging review of the September 2026 bulletin.

The Canadian Centre for Cyber Security issued advisory AV26-900 on September 9, 2026, noting that as of September 8, NVIDIA Triton Inference Server versions 0.0 to 26.03 and 0.0 to 26.06 are affected by vulnerabilities. The advisory includes no CVE identifiers or severity details and directs users to review NVIDIA's September 2026 Triton security bulletin and apply available updates.

Canadian Centre for Cyber Security · 7d agoAdvisory

Oracle Corporation security advisory (AV26-929)

CCCS relays Oracle's September 2026 Critical Patch Update fixing vulnerabilities across WebLogic, Database, E-Business Suite, PeopleSoft, Siebel, and dozens more products.

The Canadian Centre for Cyber Security (AV26-929) relays Oracle's September 2026 Critical Security Patch Update, which addresses vulnerabilities in dozens of product families as of September 15, 2026. Affected products include Oracle WebLogic Server, Database Server, E-Business Suite, Fusion Middleware, PeopleSoft Enterprise, Siebel Applications, GraalVM, VirtualBox, Coherence, and numerous banking and communications suites. The bulletin lists no CVE identifiers and encourages administrators to review Oracle's advisory and apply patches.

SAP security advisory – September 2026 monthly rollup (AV26-894)

Canada's Cyber Centre relayed SAP's September 2026 Patch Day rollup covering vulnerabilities across NetWeaver, kernel components, CAP, and Integration Suite.

The Canadian Centre for Cyber Security published advisory AV26-894 noting that as of September 8, 2026, SAP is affected by vulnerabilities in multiple products, including SAP Extended Passport, NetWeaver Message Server, SAP Cloud Application Programming Model, SAP GUI for Java, Integration Suite Cloud Integration, NetWeaver Business Client, and NetWeaver AS for ABAP. The advisory corresponds to SAP Security Patch Day September 2026 and lists many affected kernel and web dispatcher versions. Administrators are urged to review the SAP advisory and apply updates as available.

Canadian Centre for Cyber Security · 8d agoAdvisory

Dell security advisory (AV26-886)

Canada's Cyber Centre flags September 2026 Dell vulnerabilities across iDRAC9/iDRAC10, OpenManage, PowerEdge, Avamar, NetWorker VE, PowerProtect, IDPA and PowerScale OneFS.

Canadian Centre for Cyber Security advisory AV26-886 lists Dell vulnerabilities across iDRAC9, iDRAC10, OpenManage Network Integration, PowerEdge servers, the OpenManage Python SDK, Avamar, NetWorker Virtual Edition, PowerProtect DP Series, IDPA and PowerScale OneFS. Fixed versions include iDRAC9 7.30.10.50, iDRAC10 1.30.30.50 and OpenManage Network Integration 3.10. No CVE identifiers or exploitation status are provided; administrators are urged to apply the vendor updates.

Canadian Centre for Cyber Security · 8d agoAdvisory

Orthanc DICOM Server

CISA advisory flags CVE-2026-87020, an integer overflow in Orthanc DICOM Server <1.13.0 causing heap out-of-bounds write and denial of service when decoding crafted PNG/JPEG images.

CISA published ICSMA-26-253-02 for Orthanc DICOM Server versions below 1.13.0, used in healthcare environments worldwide. CVE-2026-87020 (CWE-190) is an integer overflow in pitch and buffer-size computation causing a heap out-of-bounds write when decoding attacker-supplied PNG or JPEG images. An authenticated remote attacker can crash the Orthanc process and cause denial of service; CVSS v3.1 is 8.1 HIGH. CISA states no known public exploitation targeting this flaw has been reported.

CISA Advisories · 6d agoAdvisoryCVE-2026-87020