Why Should I Care? β€” 2026-08-14 | πŸ”΄ 3 HIGH Β· 🟑 11 MEDIUM Β· πŸ”΅ 12 RADAR Β· βšͺ 235 FILTERED

πŸ“‹ Briefing β€” 2026-08-14

26 vendor intel items scanned  |  πŸ”΄ 3 HIGH  |  🟑 11 MEDIUM  |  πŸ”΅ 12 RADAR  |  βšͺ 235 FILTERED

πŸ”΄ Critical β€” action required:

  1. AVEVA Enterprise SCADA (CVE-2025-7639) β€” Yes, if you run AVEVA Enterprise SCADA versions 2021_SP2_P5 and below, or any version up to 2025: authenticated attackers can execute code via deserialization.
  2. Haiwell IoT Cloud HMI Gateway (CVE-2026-19188) β€” Yes, if you run Haiwell IoT Cloud HMI Gateway 3.40.1.12: critical OS command injection vulnerability allows unauthenticated attackers to execute arbitrary commands with root privileges.
  3. Siemens Siveillance Video (CVE-2026-3014) β€” Yes, if you run Siemens Siveillance Video versions V2023 R3 < 23.3.27, V2024 R1 < 24.1.16, or V2025 < 25.1.15: unauthenticated remote code execution is possible via OS command injection.

Everything else can wait.

🟑 Medium β€” review when time permits:

  1. AWS Certificate Manager will discontinue email validation to prove domain validation for certificates β€” Skip this if you do not use email validation for your ACM public certificates.
  2. Hitachi Energy APM Edge Product β€” Yes, if you run Hitachi Energy APM Edge versions <=6.10: local unprivileged users can escalate privileges to root via Dirty Frag vulnerabilities.
  3. Siemens Simcenter Femap β€” Yes, if you run Simcenter Femap < V2606.0001: unpatched BMP file parsing vulnerabilities could lead to application crashes or arbitrary code execution.
  4. Siemens Solid Edge β€” Yes, if you run Solid Edge SE2025 < 225.0.15 or SE2026 < 226.0.7: multiple vulnerabilities allow arbitrary code execution via crafted files.
  5. ANDRITZ HIPASE-250 and 250 SCALA β€” Yes, if you run HIPASE-250 <=7.20 or 250 SCALA <=7.20: unauthenticated access to sensitive data and configuration changes possible.
  6. Siemens LOGO! Soft Comfort β€” Yes, if you run LOGO! Soft Comfort < V9: local attacker can extract master key and decrypt project data or remove passwords.
  7. Flow Neuroscience FL-100 β€” Yes, if you use Flow Neuroscience FL-100 or Halo Neuroscience FL-100 before July_2026: an attacker within Bluetooth range can manipulate brain stimulation parameters and override safety limits using a hard-coded credential.
  8. Johnson Controls Metasys β€” Yes, if you run Metasys versions 12-15: low-privilege users can inject XSS payloads that hijack sessions and gain unauthorized access.
  9. Siemens Desigo DXR and PXC Controllers β€” Yes, if you run Siemens Desigo DXR2 < V01.21.233.16-7862 or PXC controllers < V02.21.194.36-2715: unpatched devices can be knocked offline by malformed BACnet packets, requiring manual reset.
  10. Siemens License Server (SLS) β€” Yes, if you run Siemens License Server (SLS) versions less than 5.1 or less than 5.3: multiple vulnerabilities allow privilege escalation and file access, leading to full system compromise.
  11. ... and 1 more

πŸ”΅ 12 items on the radar β€” see below ↓


Why Should I Care? πŸ”΄ HIGH β€” Handle Now


AVEVA Enterprise SCADA

CISA Advisories | CVSS 7.1 | CVE-2025-7639

❓ Why Should I Care?
Yes, if you run AVEVA Enterprise SCADA versions 2021_SP2_P5 and below, or any version up to 2025: authenticated attackers can execute code via deserialization. Patch now.

🎯 Affected versions: Enterprise SCADA <=2021_SP2_P5, >=2022|<=2022_SP2_P2, >=2023|<=2023_SP1, >=2024|<=2024_SP1_P01, 2025; Enterprise SCADA HMI <=2023_P1, 2024_R2

🎭 In plain English:
An attacker with 'DNA Authority - Operator' privileges can manipulate serialized data to execute arbitrary code. This means they could run malicious software on your system, potentially taking control of it and altering critical operations.

πŸ”§ Prerequisites:

  • Authenticated access with 'DNA Authority - Operator' privilege

⏱ Urgency: High urgency due to the potential for authenticated attackers to gain unauthorized execution capabilities.

πŸ’‘ Context: The vulnerability arises from improper handling of serialized data, allowing an attacker to inject malicious code during deserialization.

βœ… Fixed in: 2025 P1, 2024 SP1 P2, 2023 SP1 P1, 2022 SP2 P3, 2021 SP2 P6


Haiwell IoT Cloud HMI Gateway

CISA Advisories | CVSS 10 | CVE-2026-19188

❓ Why Should I Care?
Yes, if you run Haiwell IoT Cloud HMI Gateway 3.40.1.12: critical OS command injection vulnerability allows unauthenticated attackers to execute arbitrary commands with root privileges.

🎯 Affected versions: Haiwell IoT Cloud HMI Gateway 3.40.1.12

🎭 In plain English:
An attacker can send a specially crafted request to your device and execute any command on the underlying operating system with full administrative rights, essentially taking complete control of your gateway.

πŸ”§ Prerequisites:

  • Access to /setting endpoint
  • Unpatched Haiwell IoT Cloud HMI Gateway 3.40.1.12

⏱ Urgency: High urgency due to critical severity and potential for unauthenticated remote code execution with root privileges.

πŸ’‘ Context: The cmdPing Socket.io event in the Net Check feature fails to sanitize user-supplied input, allowing injection of arbitrary OS commands.

βœ… Fixed in: Scada-v3.50.1.19


Siemens Siveillance Video

CISA Advisories | CVSS 9.1 | CVE-2026-3014

❓ Why Should I Care?
Yes, if you run Siemens Siveillance Video versions V2023 R3 < 23.3.27, V2024 R1 < 24.1.16, or V2025 < 25.1.15: unauthenticated remote code execution is possible via OS command injection.

🎯 Affected versions: Siveillance Video V2023 R3 < 23.3.27, Siveillance Video V2024 R1 < 24.1.16, Siveillance Video V2025 < 25.1.15

🎭 In plain English:
An attacker can execute any command on your video management server without needing a password or special permissions. This means they could take full control of the device and potentially access all the cameras' feeds, modify settings, or even crash the system.

πŸ”§ Prerequisites:

  • User with edit permissions to the Management Server

⏱ Urgency: High urgency due to the potential for unauthenticated remote code execution which can lead to complete server compromise.

πŸ’‘ Context: The Management Server API improperly handles special elements used in OS commands, allowing for command injection.

βœ… Fixed in: V23.3 HotfixRev27, V24.1 HotfixRev16, V25.1 HotfixRev15


Why Should I Care? 🟑 MEDIUM (11)


AWS Certificate Manager will discontinue email validation to prove domain validation for certificates

AWS Security Blog

❓ Why Should I Care?
Skip this if you do not use email validation for your ACM public certificates. By September 30, 2027, email validation will no longer be supported.

🎯 Affected versions: AWS

🎭 In plain English:
AWS Certificate Manager (ACM) is ending support for email-validated certificates. If you rely on email validation to prove domain ownership, you need to switch to DNS validation before September 30, 2027.

⏱ Urgency: Low urgency as the deadline is set for September 30, 2027, but it's recommended to start planning your migration now.


Hitachi Energy APM Edge Product

CISA Advisories | CVSS ['8.8', '7.8'] | ['CVE-2026-43284', 'CVE-2026-43500']

❓ Why Should I Care?
Yes, if you run Hitachi Energy APM Edge versions <=6.10: local unprivileged users can escalate privileges to root via Dirty Frag vulnerabilities.

🎯 Affected versions: APM Edge versions <=6.10

🎭 In plain English:
An attacker with local access to your Hitachi Energy APM Edge device can exploit a flaw in the Linux kernel to run any command as root, effectively taking full control of the system without needing admin credentials.

πŸ”§ Prerequisites:

  • Local unprivileged user access

⏱ Urgency: High urgency due to the potential for privilege escalation and complete compromise of affected devices by local attackers.

πŸ’‘ Context: The kernel modules (esp4, esp6, rxrpc) improperly handle memory pages when processing encrypted network packets, allowing an attacker to inject malicious code into system binaries.


Siemens Simcenter Femap

CISA Advisories | CVSS 7.8 | CVE-2026-59700, CVE-2026-59701

❓ Why Should I Care?
Yes, if you run Simcenter Femap < V2606.0001: unpatched BMP file parsing vulnerabilities could lead to application crashes or arbitrary code execution.

🎯 Affected versions: Simcenter Femap < V2606.0001

🎭 In plain English:
If you open a specially crafted BMP file in Simcenter Femap, an attacker could crash the application or execute arbitrary code on your system. For example, if you're tricked into opening a malicious image file, it could allow someone to take control of your computer and perform actions like stealing sensitive data or installing malware.

πŸ”§ Prerequisites:

  • User must open a specially crafted BMP file
  • Application version is < V2606.0001

⏱ Urgency: High urgency due to the potential for arbitrary code execution, which could lead to system compromise.

πŸ’‘ Context: The application fails to properly validate BMP file contents, leading to out-of-bounds read vulnerabilities.

βœ… Fixed in: V2606.0001


Siemens Solid Edge

CISA Advisories | CVSS 7.8 | CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064

❓ Why Should I Care?
Yes, if you run Solid Edge SE2025 < 225.0.15 or SE2026 < 226.0.7: multiple vulnerabilities allow arbitrary code execution via crafted files.

🎯 Affected versions: Solid Edge SE2025 < 225.0.15, Solid Edge SE2026 < 226.0.7

🎭 In plain English:
If you open a specially crafted file in Solid Edge, an attacker can execute arbitrary code on your system. This means they could run any program or command as if they were logged into your machine.

πŸ”§ Prerequisites:

  • User must open a maliciously crafted PAR, PSM, or DFT file

⏱ Urgency: High urgency due to the potential for remote code execution and the availability of patches.

πŸ’‘ Context: The application fails to properly validate input files, leading to out-of-bounds reads/writes and use-after-free vulnerabilities.

βœ… Fixed in: 225.0.15, 226.0.7


ANDRITZ HIPASE-250 and 250 SCALA

CISA Advisories | CVSS 8.1 | CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313

❓ Why Should I Care?
Yes, if you run HIPASE-250 <=7.20 or 250 SCALA <=7.20: unauthenticated access to sensitive data and configuration changes possible.

🎯 Affected versions: HIPASE-250 <=7.20, 250 SCALA <=7.20

🎭 In plain English:
Your ANDRITZ device stores passwords in a way that can be easily read and allows anyone on the network to access sensitive data without needing any credentials. An attacker could log in as an admin, change settings, or even disable logging to hide their actions.

πŸ”§ Prerequisites:

  • Network access to the device

⏱ Urgency: High urgency due to potential for unauthenticated access and data theft.

πŸ’‘ Context: The device uses reversible password storage and exposes critical functions without authentication.

βœ… Fixed in: V8.00.00, V8.15.00


Siemens LOGO! Soft Comfort

CISA Advisories | CVSS 6.8 | CVE-2026-57262, CVE-2026-57263

❓ Why Should I Care?
Yes, if you run LOGO! Soft Comfort < V9: local attacker can extract master key and decrypt project data or remove passwords. Patch now.

🎯 Affected versions: LOGO! Soft Comfort < V9

🎭 In plain English:
Your LOGO! Soft Comfort software uses a weak encryption method that allows an attacker with physical access to your device to steal the master key and decrypt sensitive project data or remove passwords. This means they can view or modify your project logic without needing any password.

πŸ”§ Prerequisites:

  • Physical access to the device
  • Running version < V9

⏱ Urgency: High urgency due to the risk of unauthorized access and modification of critical project data.

πŸ’‘ Context: The software uses a hard-coded cryptographic key for encryption, which can be extracted by an attacker. Additionally, passwords are stored as unsalted hashes, making them vulnerable to brute-force attacks.

βœ… Fixed in: V9


Flow Neuroscience FL-100

CISA Advisories | CVSS 8.1 | CVE-2026-18164

❓ Why Should I Care?
Yes, if you use Flow Neuroscience FL-100 or Halo Neuroscience FL-100 before July_2026: an attacker within Bluetooth range can manipulate brain stimulation parameters and override safety limits using a hard-coded credential.

🎯 Affected versions: Flow Neuroscience FL-100 < July_2026, Halo Neuroscience FL-100 < July_2026

🎭 In plain English:
Your brain stimulation device has a hidden password that anyone can use to change its settings. An attacker nearby could adjust the electrical impulses sent to your brain without your knowledge, potentially causing harm or altering intended treatment outcomes.

πŸ”§ Prerequisites:

  • Bluetooth range access
  • Device firmware version before July_2026

⏱ Urgency: High urgency due to the potential for immediate and serious physical harm if exploited.

πŸ’‘ Context: The device uses a hard-coded credential that allows unauthorized users to bypass authentication and manipulate brain stimulation parameters.


Johnson Controls Metasys

CISA Advisories | CVSS 8 | CVE-2026-34491

❓ Why Should I Care?
Yes, if you run Metasys versions 12-15: low-privilege users can inject XSS payloads that hijack sessions and gain unauthorized access. Patch now.

🎯 Affected versions: Metasys 12: all, Metasys 13: all, Metasys 14:Not affected: Metasys 16 and earlier versions (11 & prior)

🎭 In plain English:
A low-privilege user can insert malicious code into the Metasys UI via a crafted URL, which executes in other users' browser sessions, including admins. This allows them to hijack sessions and gain unauthorized access.

πŸ”§ Prerequisites:

  • User must be able to craft and inject URLs
  • Targeted users must visit the injected URL

⏱ Urgency: High urgency due to potential for session hijacking by low-privilege users or attackers, leading to unauthorized access.

πŸ’‘ Context: The Metasys UI does not properly sanitize input from URLs, allowing XSS payloads to persist and execute in other user sessions.

βœ… Fixed in: 14.1.5, 15.0.1


Siemens Desigo DXR and PXC Controllers

CISA Advisories | CVSS 4.3 | CVE-2026-59693

❓ Why Should I Care?
Yes, if you run Siemens Desigo DXR2 < V01.21.233.16-7862 or PXC controllers < V02.21.194.36-2715: unpatched devices can be knocked offline by malformed BACnet packets, requiring manual reset.

🎯 Affected versions: Desigo DXR2 < V01.21.233.16-7862, Desigo PXC3 < V01.21.233.16-7862, Desigo PXC4 < V02.21.194.36-2715, Desigo PXC5.E003 < V02.21.194.36-2715, Desigo PXC5.E24 < V02.21.194.36-2715, Desigo PXC7 < V02.21.194.36-2715

🎭 In plain English:
Your Siemens controllers can be made to stop working by sending them bad data packets. This means your HVAC or building automation systems could suddenly go offline, and you'd need to manually reset the devices to get them back online.

πŸ”§ Prerequisites:

  • The attacker must be able to send BACnet packets to the affected device.

⏱ Urgency: Moderately urgent β€” while not leading to data theft, a denial of service can disrupt operations until manual intervention.

πŸ’‘ Context: The controllers fail to properly handle malformed BACnet packets, leading to a denial of service condition.

βœ… Fixed in: V01.21.233.16-7862, V02.21.194.36-2715


Siemens License Server (SLS)

CISA Advisories | CVSS 7.5 | ['CVE-2026-69108', 'CVE-2026-69109']

❓ Why Should I Care?
Yes, if you run Siemens License Server (SLS) versions less than 5.1 or less than 5.3: multiple vulnerabilities allow privilege escalation and file access, leading to full system compromise.

🎯 Affected versions: Siemens License Server (SLS) versions less than 5.1, and versions less than 5.3

🎭 In plain English:
Your license server has security holes that let attackers gain full control over it. They can read any file on the system and even execute commands as if they were an admin. This means they could steal sensitive data or install malware.

πŸ”§ Prerequisites:

  • Local access for CVE-2026-69108
  • Remote access for CVE-2026-69109

⏱ Urgency: High urgency due to the potential for full system compromise and active exploitation risk.

πŸ’‘ Context: CVE-2026-69108: Insecure sudoers policy allows privilege escalation; CVE-2026-69109: Lack of input sanitization enables path traversal.

βœ… Fixed in: 5.1, 5.3


Siemens Parasolid

CISA Advisories | CVSS 7.8 | CVE-2026-64629

❓ Why Should I Care?
Yes, if you run Siemens Parasolid V38.0 < V38.0.235 or V38.1 < V38.1.230: an attacker could crash the application or execute arbitrary code via specially crafted X_T files.

🎯 Affected versions: Parasolid V38.0 < V38.0.235, Parasolid V38.1 < V38.1.230

🎭 In plain English:
If you use an older version of Siemens Parasolid, a hacker could send your software a specially crafted file that causes it to crash or run malicious code. This means the attacker could take control of your application and potentially access sensitive data.

πŸ”§ Prerequisites:

  • The application must be configured to read X_T files.

⏱ Urgency: High urgency due to the potential for arbitrary code execution, which can lead to full compromise of the affected system.

πŸ’‘ Context: The vulnerability stems from an out-of-bounds read while parsing X_T files, allowing attackers to exploit memory corruption.

βœ… Fixed in: V38.0.235, V38.1.230


Why Should I Care? πŸ”΅ On the Radar (12)


βšͺ 235 low-priority items filtered.


πŸ¦… Aggregated and triaged by Donna AI  |  Sources: 9 vendor feeds  |  CISA KEV

Read more

Why Should I Care? β€” 2026-09-24 | πŸ”΄ 0 HIGH Β· 🟑 0 MEDIUM Β· πŸ”΅ 27 RADAR Β· βšͺ 69 FILTERED

πŸ“‹ Briefing β€” 2026-09-24 27 vendor intel items scanned Β |Β  πŸ”΄ 0 HIGH Β |Β  🟑 0 MEDIUM Β |Β  πŸ”΅ 27 RADAR Β |Β  βšͺ 69 FILTERED βœ… No critical items today. Everything else can wait. πŸ”΅ 15 items on the radar β€” see below ↓ Why Should I Care? πŸ”΄ HIGH β€” Handle Now No HIGH priority items in the last 24h. Why Should I Care? 🟑 MEDIUM

By Josip Sokolovic

Why Should I Care? β€” 2026-09-23 | πŸ”΄ 5 HIGH Β· 🟑 3 MEDIUM Β· πŸ”΅ 27 RADAR Β· βšͺ 69 FILTERED

πŸ“‹ Briefing β€” 2026-09-23 35 vendor intel items scanned Β |Β  πŸ”΄ 5 HIGH Β |Β  🟑 3 MEDIUM Β |Β  πŸ”΅ 27 RADAR Β |Β  βšͺ 69 FILTERED πŸ”΄ Critical β€” action required: 1. CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127) β€” Yes, if you run any affected versions of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM: these vulnerabilities

By Josip Sokolovic

Why Should I Care? β€” 2026-09-22 | πŸ”΄ 1 HIGH Β· 🟑 0 MEDIUM Β· πŸ”΅ 17 RADAR Β· βšͺ 66 FILTERED

πŸ“‹ Briefing β€” 2026-09-22 18 vendor intel items scanned Β |Β  πŸ”΄ 1 HIGH Β |Β  🟑 0 MEDIUM Β |Β  πŸ”΅ 17 RADAR Β |Β  βšͺ 66 FILTERED πŸ”΄ Critical β€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-7273) β€” Yes, if you run Zyxel GS1900 Series Switches: This vulnerability can allow attackers to take full control of your switch. Everything else

By Josip Sokolovic

Why Should I Care? β€” 2026-09-21 | πŸ”΄ 23 HIGH Β· 🟑 32 MEDIUM Β· πŸ”΅ 209 RADAR Β· βšͺ 73 FILTERED

πŸ“‹ Briefing β€” 2026-09-21 264 vendor intel items scanned Β |Β  πŸ”΄ 23 HIGH Β |Β  🟑 32 MEDIUM Β |Β  πŸ”΅ 209 RADAR Β |Β  βšͺ 73 FILTERED πŸ”΄ Critical β€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-76461) β€” Yes, if you run Cisco Secure Email Gateway versions 12.0.0 - 12.0.4: SQL injection vulnerability, actively exploited in

By Josip Sokolovic