September 2, 2026
A high-severity vulnerability in Rently Smart Home versions 20.1.0 and prior could allow unauthorized retrieval of Master Pins, potentially granting attackers elevated permissions within commercial facility automation environments.
Read the analysis →
September 2, 2026
A critical vulnerability (CVE-2026-76060) allows authenticated users with specific permissions to execute arbitrary OS commands on Zoneminder servers used for industrial physical security monitoring.
Read the analysis →
September 2, 2026
Multiple critical vulnerabilities in the Ebyte NE2-D11 gateway could allow unauthorized administrative access and disruption of operations; currently, no patch is available from the vendor.
Read the analysis →
September 2, 2026
A vulnerability in the bcrypt implementation of Rockwell Automation OTTO Fleet Manager could allow attackers to perform offline brute-force attacks against password hashes if they obtain an unencrypted system backup.
Read the analysis →
September 2, 2026
CISA has issued an advisory for the Xiiaozet LK100W, identifying three critical vulnerabilities that could allow remote attackers to bypass authentication and execute arbitrary OS commands.
Read the analysis →
September 2, 2026
A vulnerability in several Mitsubishi Electric CNC series products could allow a remote attacker to trigger a denial-of-service condition via TCP port 683.
Read the analysis →
September 2, 2026
A vulnerability (CVE-2025-3511) affecting multiple Mitsubishi Electric iQ-R and iQ-F series components could allow remote attackers to cause denial-of-service conditions or communication delays via crafted UDP packets.
Read the analysis →
September 2, 2026
A series of critical vulnerabilities in the Ebyte NA111-M gateway could allow remote attackers to fully compromise the device. With no patch currently available, OT operators must prioritize network isolation.
Read the analysis →
September 2, 2026
CISA has issued an advisory for multiple remote code execution vulnerabilities affecting All-Line Equipment Company Fuel-Boss systems used in critical manufacturing and transportation sectors.
Read the analysis →
September 2, 2026
Two critical vulnerabilities affecting the ASE2000 V2 Communications Test Set could allow arbitrary file access and TLS impersonation in industrial environments. Asset owners should evaluate version applicability and prioritize updates to version…
Read the analysis →