Cyber Security News

CIS Security Advisories

CIS Security News

CISA News

ISACA SmartBrief

RSS feed: Cyber Security Advisories – MS-ISAC Cyber Security Advisories – MS-ISAC
  • Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution 2026-09-02
    Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install […]
  • Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code Execution 2026-08-19
    Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; […]
  • Multiple Vulnerabilities in SonicWall GMS Could Allow for Remote Code Execution 2026-08-12
    Multiple vulnerabilities have been discovered in SonicWall Global Management System (GMS), the most severe of which could allow for remote code execution. The SonicWall Global Management System (GMS) is a centralized management interface used to deploy and centrally manage SonicWall firewall, wireless, email security, secure remote access and Dell X-Series solutions from a single console. […]
  • Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution 2026-08-12
    Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install […]
  • A Vulnerability in Zoom Clients Could Allow for Remote Code Execution 2026-08-12
    A vulnerability has been discovered in Zoom Clients that could allow for remote code execution. Zoom is a cloud-based communications platform that allows users to connect via video, audio, chat, and content sharing. Successful exploitation could allow an attacker to target meeting participants, execute code without user interaction, steal data, activate cameras or microphones, and […]
  • Critical Patches Issued for Microsoft Products, August 11, 2026 2026-08-11
    Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; […]
  • Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution 2026-08-11
    Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe ColdFusion is a commercial rapid web application development platform and application server.Adobe Commerce is an enterprise-level e-commerce platform built on the proven technology of Magento.Adobe Lightroom is a popular cloud-based image organization and photo-editing software developed […]
  • Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution 2026-08-07
    Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install […]
  • Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass 2026-08-03
    Multiple vulnerabilities have been discovered in SolarWinds Web Help Desk, the most severe of which could allow for authentication bypass. SolarWinds Web Help Desk software grants access to SolarWinds IT support, asset management, and knowledge base operations. A vulnerability in the Web Help Desk could allow an unauthenticated, remote attacker to bypass authentication and gain […]
  • Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution 2026-07-30
    Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install […]
RSS feed: Blog Feed – Center for Internet Security Blog Feed – Center for Internet Security
RSS feed: All CISA Advisories All CISA Advisories
  • CISA Adds Seven Known Exploited Vulnerabilities to Catalog 2026-09-02
    CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability  CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability  CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability  CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability  CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability  CVE-2026-83548 SonicWall SMA1000 […]
    CISA
  • Communicating Under Pressure: Best Practices for Service Providers 2026-09-02
    Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even […]
    CISA
  • Rockwell Automation FactoryTalk Activation Manager 2026-09-01
    View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All […]
    CISA
  • Rockwell Automation Redundancy Module Configuration Tool 2026-09-01
    View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633) Redundancy Module Configuration Tool >=9.00.00|
    CISA
  • Rockwell Automation Logix Platform 2026-09-01
    View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580
    CISA
  • Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix 2026-09-01
    View CSAF Summary The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected: ControlLogix 5580
    CISA
  • Rockwell Automation Historian ME 2026-09-01
    View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME […]
    CISA
  • Rockwell Automation RSLinx Classic 2026-09-01
    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx Classic
    CISA
  • CISA Adds Two Known Exploited Vulnerabilities to Catalog 2026-08-31
    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability  CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability  These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal […]
    CISA
  • Applied Systems Engineering ASE2000 V2 Communications Test Set 2026-08-27
    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications. The following versions of Applied Systems Engineering ASE2000 […]
    CISA
RSS feed: ISACA SmartBrief on Cybersecurity ISACA SmartBrief on Cybersecurity
Ohio Department of Education & Workforce
MS-ISAC
CIS-Logo
Management Council Logo