Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
CISA published an advisory on vulnerabilities in Johnson Controls C-CURE 9000 and Victor application server used for physical access control. Exploitation could lead to authentication bypass and system compromise.
CISA issued a critical advisory on vulnerabilities in the Johnson Controls XAAP Android application used for building management. These flaws could enable remote compromise of access control and environmental systems.
CISA published a critical advisory on vulnerabilities in the Weintek cMT3092X HMI device used across industrial sectors. These flaws could enable remote attackers to gain unauthorized control of the interface.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code.
This CISA advisory covers multiple vulnerabilities in MZ Automation libIEC61850, including stack and heap buffer overflows, null pointer dereference, and improper invalid structure handling. Successful exploitation could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code.
This CISA advisory describes CVE-2026-11917, a path traversal vulnerability in Rockwell Automation ThinManager. An authenticated attacker can exploit improper file save operation limits to write arbitrary files to restricted system directories.