Updated just now ยท 13 advisories
An attacker on the radio frequency link could inject unauthorized messages into CPDLC communications, reset pilot-controller sessions, or cause denial-of-service conditions that delay safety-critical instructions and increase pilot workload during critical flight phases.
An attacker with high-privilege access to the network could extract sensitive information from the device, potentially including credentials or other data used to manage security cameras and related systems. This could enable lateral movement within the facility or unauthorized surveillance.
A maliciously crafted DICOM file could crash RadiAnt DICOM, interrupting medical image review workflows and potentially delaying diagnostic operations.
An authenticated attacker could crash the web management interface on a Cisco IOS XE device, temporarily preventing remote access and monitoring of the device through the GUI.
An authenticated attacker with access to SD-WAN management interfaces could execute remote commands or manipulate SD-WAN network configuration and traffic routing, potentially causing denial of service or unauthorized changes to network operations.
An attacker could send specially crafted input to bypass validation checks on Cisco IOS XE devices, potentially allowing unauthorized command execution or device manipulation that could disrupt network operations or alter router configurations.
An authenticated user with low privileges could read logs containing plaintext authentication credentials stored in the SD-WAN Manager, allowing them to compromise network infrastructure and access connected services.
An attacker could send a crafted network packet to a Cisco router or switch running affected IOS or IOS XE software, causing it to crash and reload unexpectedly. This would interrupt all traffic routing and switching until the device comes back online, taking down network connectivity for any connected segments.
An authenticated attacker with SNMP credentials could send a malformed SNMP request that crashes your Cisco router or switch, forcing it to reboot and disrupting network connectivity and any dependent operations.
An authenticated attacker with low-privilege credentials could cause a network device running Cisco IOS XE to reload and go offline, disrupting network connectivity and any dependent operations until the device restarts.
An unauthenticated attacker can send a crafted BEEP SOAP request over the network to cause a router or switch to crash and reload, resulting in loss of network connectivity and service downtime.
An attacker with local access to an IndustrialPI device could gain full control of it, allowing them to modify process setpoints, stop production, or inject malicious commands into safety-critical automation logic.
An attacker on your local network could gain control of vehicle access and security functions on KARR BT and DR-100 devices, potentially allowing unauthorized entry or disabling safety interlocks.
An attacker with network access to a CHARX SEC charging controller could run commands remotely, gain full control of the device, and manipulate or disable EV charging operations at your facility.
An attacker with low-privilege API access to your RouterOS device could extract the WireGuard private key and impersonate your VPN connection, allowing them to decrypt all traffic flowing through that VPN tunnel.
An attacker with administrative credentials could upload malicious files or inject malicious code into the OpenBlue Employee web application, potentially compromising workstations that access it or the data it stores.
An attacker on your local network could gain complete control of the RCU II+ or Multiload II+ fuel management device, allowing them to alter transaction data, manipulate fuel inventory records, or disrupt fuel distribution operations.
An attacker with network access to the Core Flight System could send crafted packets that crash the Health & Safety application, disrupting monitoring and control functions for spacecraft or satellite systems that depend on HS for health checks and anomaly detection.
An attacker with login credentials to an OPC UA server running vulnerable open62541 could trigger integer overflow or use-after-free flaws to read sensitive data, crash the server, or potentially run arbitrary code on the system hosting the OPC UA service.
An attacker with high-level access and ability to interact with the controller could deliver malicious firmware to gain full control of the Watchfire controller, potentially altering display content, timing, or operations that depend on the billboard system.
An attacker with network access to a device running vulnerable libiec61850 could trigger a denial-of-service condition, causing the device to become unresponsive or crash and disrupting any industrial processes that depend on it.
An attacker could crash a device running lib60870, disrupting communication with IEC 60870-5-104 SCADA systems. This could interrupt remote monitoring and control of critical infrastructure equipment like power distribution or water treatment systems.
An attacker with local access to a machine running ABB zenon could exploit vulnerabilities in the bundled end-of-life MongoDB to access sensitive data, disrupt system availability, or interfere with IIoT operations.
An attacker on the same network segment can intercept and modify CC-Link IE TSN communication packets to disrupt controller operations, causing devices to malfunction, stop responding, or execute unintended commands.
This is an advance notice onlyโno vulnerabilities are disclosed yet. Cisco will publish detailed security advisories on August 5, 2026, affecting network infrastructure, routing, management, and collaboration systems. Customers should plan to assess and patch affected products after the advisories are published.
An attacker can remotely log in to your Firewall Management Center using a static low-privileged account without any credentials and access sensitive configuration data and network security policies that the FMC controls.
An attacker on the local network can send malformed PROFINET packets that cause the PLC application to crash and stop, interrupting any industrial process the controller is managing.
An attacker on your local network or with access to your router's API can guess administrative passwords rapidly due to weak rate limiting, potentially gaining full control of the device and all traffic it routes.
An attacker could access backend services and functions without proper authentication, potentially gaining unauthorized control of smart locks or viewing sensitive access information.
An attacker with a regular user account on a system running an affected Linux kernel can escalate privileges to root and execute arbitrary commands, potentially gaining complete control of the device and any connected industrial systems.
An attacker with network access to the C-CURE 9000 or victor application server could execute arbitrary code on the server, potentially compromising the entire access control system and any dependent facilities or processes.
An attacker with physical access to a device running XAAP Android could read confidential information stored locally on the device, such as configuration data or access credentials used to control facility operations.
A non-privileged user with local access to a cMT3092X panel could escalate their privileges to administrator level or steal credentials of other users, potentially allowing them to modify control logic or access sensitive operational data.
An attacker on your IT network could modify settings or control commands sent to industrial devices through IntraVUE without needing credentials or physical access, potentially disrupting production or equipment operation.
An attacker on your network could crash IEC 61850 communication services (used by protection relays and SCADA systems to exchange protection and control data) or execute arbitrary code on affected devices, disrupting real-time visibility of grid/process state and ability to issue control commands.
An attacker can crash the parsing process in lib60870, causing denial of service and stopping communication with connected IEC 60870-5-104 systems, which could disrupt power distribution or water management SCADA operations.
An attacker could read stored credentials and authentication tokens, then use them to access the device and connected infrastructure. Once in, they could alter power or network settings on connected equipment, disrupting critical services or creating physical safety hazards.
An attacker with physical access to the KNX bus could manipulate device configuration or firmware, potentially rendering classic KNX devices unusable or causing unintended building automation system behavior such as loss of access control or HVAC malfunction.
An authenticated operator with access to ProAccess Space could gain administrative control over restricted areas or tenant spaces they should not have access to, potentially bypassing physical access control policies and allowing unauthorized entry into secured zones.
An attacker with local or physical access to an engineering workstation running Productivity Suite could corrupt memory or crash the application, potentially causing unintended changes to device configurations or loss of engineering access during critical operations.
An attacker could crash or disable the Core Flight System Health & Safety application, interrupting health monitoring and safety checks on spacecraft or ground-based mission-critical systems.
An attacker with admin credentials could read or delete arbitrary files on your ISE system, potentially including authentication databases, configuration files, or operational records critical to network access control.
An attacker could modify PLC program logic or firmware during development or deployment, potentially altering setpoints, disabling safeties, or corrupting control sequences that govern critical processes in water treatment, power distribution, or manufacturing facilities.
A buffer overflow in Rockwell PLCs could allow an attacker to execute arbitrary code on the controller, potentially disrupting production processes, altering safety logic, or causing uncontrolled equipment operation.
An attacker with network access to these Ethernet communication modules can send specially crafted packets that cause the device to stop responding, disrupting communication with PLCs and other devices on your industrial network until the module is manually reset.
An attacker could send specially crafted network messages to a 1734 POINT I/O module, causing it to stop responding and halt I/O operations until it is manually rebooted. This would interrupt any process that depends on those input or output signals.
An attacker can remotely crash the 1718-AENTR/1719-AENTR Ethernet adapter, forcing a manual restart and causing loss of network communication with connected control systems until the device recovers.
An attacker can remotely disable the Flex 5000 Adapter, causing it to stop processing communications from connected devices. This would interrupt data flow between your control systems and field devices, potentially halting production or affecting real-time process monitoring.
An attacker with access to FactoryTalk DataMosaix Private Cloud could inject malicious code that executes when other authorized users view affected pages, potentially allowing credential theft or unauthorized commands to be issued within the system.
An attacker with network access to Arena could trigger a memory corruption flaw that causes the application to crash or potentially execute arbitrary code, disrupting engineering workflow and plant modeling operations.