#advisory

36 posts · Last used 8d

Back to Timeline
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 06, 2026

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/veeam-patches-critical-credential-theft-and-rce-flaws-in-service-provider-console-y-k-8-e-6/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 06, 2026

Django Patches High-Severity File-Write Flaw in GeoDjango and Three Other Vulnerabilities

Django 6.0.8 and 5.2.17 are out, fixing four security issues: most urgently a GeoDjango flaw (CVSS 8.8) that lets any staff user with view permission on a spatial-field model trigger SSRF or file writes, potentially leading to remote code execution.

If you run Django, upgrade now to Django 6.0.8 or 5.2.17. If you're on an older unsupported version like 5.1, 5.0 or 4.2, assume you're vulnerable and plan a move to a supported branch. If you use GeoDjango, test your spatial lookups before deploying because the fix intentionally breaks some old behaviour, and check who has staff/view access to models with map or location fields. That level of access is all an attacker needs for the most serious flaw. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/django-patches-high-severity-file-write-flaw-in-geodjango-and-three-other-vulnerabilities-d-x-1-q-e/gD2P6Ple2L

0
0
0
CERT@VDE @certvde@infosec.exchange · Aug 03, 2026
#OT #Advisory VDE-2026-065 Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory. #CVE CVE-2026-9593 https://certvde.com/en/advisories/vde-2026-065/ #CSAF https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-065.json
0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 31, 2026

IBM Patches Critical Remote Code Execution and Privilege Escalation Flaws in WebSphere

IBM issued emergency patches for WebSphere Application Server to fix four vulnerabilities, including two critical flaws with CVSS scores of 9.8. These vulnerabilities allow unauthenticated attackers to execute code, escalate privileges, and perform server-side request forgery.

If you run IBM WebSphere Application Server (traditional 8.5 or 9.0) or WebSphere Liberty, plan a quick patch. Update to packs 9.0.5.29 or 8.5.5.31 for traditional WebSphere, or upgrade Liberty to 26.0.0.9. WebSphere systems may be exposed to the internet by design, so prioritize those systems. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/ibm-patches-critical-remote-code-execution-and-privilege-escalation-flaws-in-websphere-7-h-7-4-3/gD2P6Ple2L

0
0
0
CERT@VDE @certvde@infosec.exchange · Jul 30, 2026
#OT #Advisory VDE-2026-008 Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability. #CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102 https://certvde.com/en/advisories/vde-2026-008/ #CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
0
0
0
CERT@VDE @certvde@infosec.exchange · Jul 29, 2026
#OT #Advisory VDE-2026-041 CODESYS PROFINET Controller - Out-of-bounds Write CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. #CVE CVE-2026-35226 https://certvde.com/en/advisories/vde-2026-041/ #CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-06_vde-2026-041.json
0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 28, 2026

JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution

JetBrains patched a critical authentication bypass (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated remote code execution. The flaw affects all on-premises versions and could lead to a full takeover of CI/CD pipelines.

If you run TeamCity On-Premises, urgently update to version 2025.11.7 or 2026.1.3 to patch CVE-2026-63077. All on-premises versions are vulnerable to a full server takeover. TeamCity Cloud is already patched and needs no action. If you can't update right away, install the security patch plugin (for versions 2017.1 and later) and restrict access to your TeamCity server to trusted internal networks or a VPN. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/jetbrains-fixes-critical-teamcity-authentication-bypass-allowing-remote-code-execution-c-x-w-3-z/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 28, 2026

GitLab Remote Code Execution Chain Exploits Long-Standing Memory Flaws in Oj Parser

GitLab patched a critical remote code execution chain involving two memory corruption flaws in the Oj Ruby JSON parser that allow authenticated users to take over servers via malicious Jupyter notebook diffs.

If you run self-managed GitLab, upgrade immediately to version 18.10.8, 18.11.5, or 19.0.2. There's a working exploit published and any user who can push code to a project can take over the server. If you're on version 15.2 through 18.9, those are no longer supported and won't get a patch, so you must move to a supported release to be protected. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/gitlab-remote-code-execution-chain-exploits-long-standing-memory-flaws-in-oj-parser-q-z-g-i-b/gD2P6Ple2L

1
0
0
CERT@VDE @certvde@infosec.exchange · Jul 28, 2026
#OT #Advisory VDE-2026-085 Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands. #CVE CVE-2026-16462 https://certvde.com/en/advisories/vde-2026-085/ #CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-085.json
0
0
0
CERT@VDE @certvde@infosec.exchange · Jul 28, 2026
#OT #Advisory VDE-2026-081 Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0. #CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510 https://certvde.com/en/advisories/vde-2026-081/ #CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
0
0
0
CERT@VDE @certvde@infosec.exchange · Jul 28, 2026
#OT #Advisory VDE-2026-076 ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0. #CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510 https://certvde.com/en/advisories/vde-2026-076/ #CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
0
0
0
CERT@VDE @certvde@infosec.exchange · Jul 27, 2026
#OT #Advisory VDE-2026-077 Lenze: Incorrect signature validation in the enable SSH routine The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device. #CVE CVE-2026-14837 https://certvde.com/en/advisories/vde-2026-077/ #CSAF https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-077.json
0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 23, 2026

Adobe Acrobat Extension Flaw HermeticReader Allowed Silent WhatsApp Data Theft

Adobe patched a high-severity vulnerability dubbed HermeticReader (CVE-2026-48294) in its Acrobat Chrome extension that allowed malicious websites to silently steal WhatsApp Web chat data and contacts.

If you use the Adobe Acrobat extension in Chrome, open your browser's extensions page and confirm it is running version 26.5.2.3 or later. Adobe already pushed the fix automatically, so most users are covered, but do verify yourself. If you can't confirm the version, remove the extension until you can verify. If you use WhatsApp Web on that browser, log out and re-link your device to invalidate any session an attacker could have touched. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/adobe-acrobat-extension-flaw-hermeticreader-allowed-silent-whatsapp-data-theft-6-w-7-t-g/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 23, 2026

SolarWinds Patches 15 Critical Vulnerabilities in Serv-U Managed File Transfer

SolarWinds released Serv-U 2026.3 to fix 15 critical vulnerabilities and one medium-severity flaw that allow remote code execution, privilege escalation, and account takeover.

If you use SolarWinds Serv-U Managed File Transfer software, update to version 2026.3 ASAP. After updating, turn on multi-factor authentication for all your Active Directory and LDAP users for added protection. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/solarwinds-patches-15-critical-vulnerabilities-in-serv-u-managed-file-transfer-l-j-4-9-9/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 23, 2026

Oracle Issues Record-Breaking July 2026 Security Update with 1,449 Patches

Oracle's July 2026 Critical Patch Update addresses a record 1,434 unique vulnerabilities across 334 products, including ten CVSS 10.0 flaws in Fusion Middleware and a critical E-Business Suite RCE exploited in the Estée Lauder data breach.

Apply Oracle's July 2026 Critical Patch Update as soon as possibla. Prioritize the internet-facing systems and the critical (CVSS 9.8 to 10.0) flaws that attackers can exploit remotely without any login. If you can't patch right away, block the network access to the systems and limit user privileges. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/oracle-issues-record-breaking-july-2026-security-update-with-1449-patches-n-s-h-w-j/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 22, 2026

Siemens Patches Multiple Vulnerabilities in SIDIS Secured SmartPlug

Siemens released security updates for the SIDIS Secured SmartPlug to fix 12 vulnerabilities, including a critical flaw in wireless authentication components. These flaws allow remote code execution, unauthorized access, and sensitive data disclosure in critical manufacturing environments.

Make sure your SIDIS Secured SmartPlug devices are isolated from the internet and reachable only from trusted networks, behind a firewall separated from your business network. Then update every affected device to version V7.26.0310 or later. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/siemens-patches-multiple-vulnerabilities-in-sidis-secured-smartplug-8-t-0-n-s/gD2P6Ple2L

0
0
0