ZeroHour

Search: “improper authentication”

17 stories

[Control systems] Schneider Electric security advisory (AV26-871)

Canada's Cyber Centre relayed Schneider Electric advisories for vulnerabilities in NetBotz 5-750/755 (5.5.2 and prior) and PowerChute Serial Shutdown (1.5 and prior).

The Canadian Centre for Cyber Security issued control-systems advisory AV26-871 noting Schneider Electric products affected by vulnerabilities as of September 1, 2026. Affected products include NetBotz 5-750/755 versions 5.5.2 and prior, and PowerChute Serial Shutdown versions 1.5 and prior, the latter with an improper restriction of excessive authentication attempts flaw. Administrators are urged to review Schneider Electric's security notifications and apply the suggested mitigations and updates.

Canadian Centre for Cyber Security · 13d agoAdvisory

Broken Access control on Websocket streams

Fortinet FortiSOAR access control flaw (CVSS 4.9) lets zero-permission authenticated attackers subscribe to and inject broadcast messages into websocket streams.

Fortinet advisory FG-IR-26-164 discloses an improper access control vulnerability (CWE-284, CVSSv3 4.9) in FortiSOAR. An authenticated attacker with zero permissions can subscribe to websocket streams and topics and inject broadcast messages via crafted websocket requests. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 8d agoAdvisory

CVE-2026-73195: Apache Syncope: CSV export spreadsheet formula injection

Apache Syncope CVE-2026-73195 allows authenticated users to inject spreadsheet formulas into CSV exports.

Apache Syncope disclosed CVE-2026-73195, a moderate-rated improper encoding or escaping of output vulnerability. Authenticated users can inject spreadsheet formulas into data that is later exported as CSV, which may execute when an administrator opens the file in a spreadsheet application. The flaw affects syncope-core-provisioning-java in versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2.

oss-security · 1d agoVulnerabilityCVE-2026-73195