Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This vulnerability in Mitsubishi Electric CC-Link IE TSN allows an attacker on the same network segment to send specially crafted packets under specific timing conditions to tamper with communication data. This could result in a denial-of-service condition or incorrect operation of the affected product.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.
MikroTik RouterOS has a session management flaw that allows API sessions to retain permissions after inactivity or user-group changes. An authenticated user with reduced privileges may still access sensitive data, such as the WireGuard private key.
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic.
This article covers a vulnerability in NASA's Core Flight System (cFS) Health & Safety (HS) application, tracked as CVE-2026-18064. The flaw is a NULL pointer dereference that could allow an attacker to crash the HS application, leading to a denial-of-service and processor reset.
MZ Automation lib60870 is affected by two out-of-bounds read vulnerabilities in version 2.4.0. Specially crafted IEC 60870-5-104 I-frames can cause the device to crash due to heap buffer over-read.