Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Johnson Controls Airwall versions up to 4.0.4 are impacted by a hardcoded cryptographic key (CVE-2026-64887) and an external file control vulnerability (CVE-2026-34492). Exploitation can lead to decryption of sensitive data, authentication bypass, and unauthorized file access.
Siemens License Server contains a local privilege escalation vulnerability (CVE-2026-69108) due to an insecure sudoers policy and a path traversal flaw (CVE-2026-69109) allowing remote arbitrary file access. Affected versions are below 5.1 and 5.3 respectively, and Siemens recommends updating to the latest version immediately.
Siemens Parasolid versions V38.0 before 38.0.235 and V38.1 before 38.1.230 contain an out-of-bounds read vulnerability (CVE-2026-64629) triggered by malicious X_T files. Successful exploitation could allow arbitrary code execution or application crash.
An undocumented hard-coded credential (CVE-2026-18164) in Flow Neuroscience FL-100 and Halo Neuroscience FL-100 devices permits Bluetooth attackers to manipulate brain stimulation parameters and override safety limits. All firmware versions before July 2026 are affected.
A denial-of-service vulnerability (CVE-2026-59693) in Siemens Desigo DXR and PXC controllers allows an attacker to send malformed BACnet packets, causing devices to stop responding. Affected firmware versions require a reset or reboot for recovery.
Multiple vulnerabilities in ANDRITZ HIPASE-250 and 250 SCALA (versions <=7.20) include reversible password storage (CVE-2026-65309), missing authentication (CVE-2026-65310), and hardcoded credentials (CVE-2026-65311, 65313). An attacker can exploit these to read device data or gain access to affected workstations.