Why Should I Care? โ 2026-09-18 | ๐ด 1 HIGH ยท ๐ก 7 MEDIUM ยท ๐ต 23 RADAR ยท โช 77 FILTERED
๐ Briefing โ 2026-09-18
31 vendor intel items scanned | ๐ด 1 HIGH | ๐ก 7 MEDIUM | ๐ต 23 RADAR | โช 77 FILTERED
๐ด Critical โ action required:
- ABB Ability Edgenius (CVE-2026-31431) โ Yes, if you run ABB Ability Edgenius versions >=3.2.0.0 and <3.2.4.1: This vulnerability allows local users or compromised containers to gain root access, leading to full system control.
Everything else can wait.
๐ก Medium โ review when time permits:
- Schneider Electric PowerChute Serial Shutdown โ Yes, if you run Schneider Electric PowerChute Serial Shutdown versions 1.5 and prior: you are at risk of unauthorized access due to improper authentication validation.
- Schneider Electric Modicon M340 Controller and Communication Modules โ Yes, if you run any version of Schneider Electric Modicon M340 Controller and Communication Modules prior to the fixed versions: a Denial of Service attack could render your devices unavailable.
- Schneider Electric NetBotz 5 750/755 โ Yes, if you run NetBotz 5 750/755 versions <=5.5.2: You're at risk of remote code execution and unauthorized data access.
- Bransys ELD โ Yes, if you run Bransys ELD Android version <11.00.00 or iOS version <1.1.54: Unauthorized access to telemetry data and firmware is possible.
- Hitachi Energy FACTS Control Platform (FCP) โ Yes, if you run Hitachi Energy FACTS Control Platform (FCP) versions 3.4.0 to 4.1.1 with GWS component: these vulnerabilities can allow an attacker to compromise confidentiality, integrity, and availability of your system.
- Mitsubishi Electric GX Works3 and Motion Control Settings โ Yes, if you run any version of Mitsubishi Electric GX Works3 or Motion Control Settings: this vulnerability allows local attackers to bypass authentication and modify control programs.
- Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A) โ Yes, if you run any version of the affected Mitsubishi Electric MELSEC MX Controller models or related modules: this vulnerability could allow an attacker to disrupt your control systems and cause a denial-of-service condition.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
ABB Ability Edgenius
CISA Advisories [CISA KEV] | CVSS 7.8 | CVE-2026-31431
โ Why Should I Care?
Yes, if you run ABB Ability Edgenius versions >=3.2.0.0 and <3.2.4.1: This vulnerability allows local users or compromised containers to gain root access, leading to full system control.
๐ฏ Affected versions: >=3.2.0.0 and <3.2.4.1, 3.2.4.1
๐ญ In plain English:
This vulnerability lets someone with local access or a compromised container on your system get full control. For example, an attacker could install malware, steal data, or shut down critical operations.
๐ง Prerequisites:
- Local user access
- Compromised container workload
โฑ Urgency: High urgency due to the potential for complete system control once exploited.
โ Fixed in: 3.2.4.1
๐ก Context: The root cause is a flaw in the Linux kernel's cryptographic subsystem, affecting most major Linux distributions since 2017.
Why Should I Care? ๐ก MEDIUM (7)
Schneider Electric PowerChute Serial Shutdown
CISA Advisories | CVSS 5.3 | CVE-2026-13348
โ Why Should I Care?
Yes, if you run Schneider Electric PowerChute Serial Shutdown versions 1.5 and prior: you are at risk of unauthorized access due to improper authentication validation.
๐ฏ Affected versions: 1.5 and prior
Not affected: 1.6 and later
๐ญ In plain English:
This vulnerability means an attacker could keep trying different passwords until they get in, like a burglar trying every door in a neighborhood until they find an unlocked one. Once in, they could disrupt operations and access sensitive system data.
๐ง Prerequisites:
- Redirect handling is disabled
- Access to the login interface
โฑ Urgency: Medium urgency due to the potential for unauthorized access and disruption of operations.
โ Fixed in: 1.6
๐ก Context: The root cause is the lack of proper restrictions on the number of authentication attempts, allowing brute force attacks.
Schneider Electric Modicon M340 Controller and Communication Modules
CISA Advisories | CVSS 7.5 | CVE-2025-6625
โ Why Should I Care?
Yes, if you run any version of Schneider Electric Modicon M340 Controller and Communication Modules prior to the fixed versions: a Denial of Service attack could render your devices unavailable.
๐ฏ Affected versions: All versions prior to SV3.70 for Modicon M340 Controller, all versions for M580 Global Data module, all versions for Ethernet/Serial RTU Module, versions prior to 3.60 for Modbus/TCP Ethernet Modicon M340 module, versions prior to 6.80 for Modbus/TCP Ethernet Modicon M340 FactoryCast module
๐ญ In plain English:
This vulnerability means an attacker could send a specific command to your device, causing it to crash and stop working. For example, an attacker could send a crafted FTP command that makes your device stop responding, effectively shutting down your system.
๐ง Prerequisites:
- Device must be running an affected version
- Attacker must have network access to send commands
โฑ Urgency: High urgency due to the potential for a Denial of Service attack, which could render your industrial control systems inoperable.
โ Fixed in: SV3.70 for Modicon M340 Controller, 3.60 for BMXNOE0100, 6.80 for BMXNOE0110
๐ก Context: The root cause is improper input validation, allowing crafted commands to disrupt the device's operation.
Schneider Electric NetBotz 5 750/755
CISA Advisories | CVSS 6.4 | CVE-2026-13336, CVE-2026-13337
โ Why Should I Care?
Yes, if you run NetBotz 5 750/755 versions <=5.5.2: You're at risk of remote code execution and unauthorized data access.
๐ฏ Affected versions: NetBotz 5 750 versions <=5.5.2, NetBotz 5 755 versions <=5.5.2
๐ญ In plain English:
An attacker could exploit these vulnerabilities to execute commands on your device and steal data. For example, they could remotely access your device's video feed and other environmental data.
๐ง Prerequisites:
- Access to the local network
- Possession of a maliciously modified system backup (for CVE-2026-13336)
- Logged into the web-service interface or web-ui (for CVE-2026-13337)
โฑ Urgency: High urgency due to the risk of unauthorized access and potential data theft.
โ Fixed in: 5.6.0
๐ก Context: The root cause includes improper handling of OS commands and SQL queries.
Bransys ELD
CISA Advisories | CVSS 7.5 | CVE-2026-86520, CVE-2026-86689, CVE-2026-77960
โ Why Should I Care?
Yes, if you run Bransys ELD Android version <11.00.00 or iOS version <1.1.54: Unauthorized access to telemetry data and firmware is possible.
๐ฏ Affected versions: Android <11.00.00, iOS <1.1.54
๐ญ In plain English:
This vulnerability means that if you're using an outdated version of Bransys ELD, someone could access your sensitive data and firmware without permission. For example, an attacker could read your real-time vehicle data and potentially tamper with your firmware.
๐ง Prerequisites:
- Running Bransys ELD Android version <11.00.00
- Running Bransys ELD iOS version <1.1.54
โฑ Urgency: High urgency due to the risk of unauthorized access to sensitive data and firmware.
โ Fixed in: Android 11.00.00, iOS 1.1.54
๐ก Context: The root cause is the use of hard-coded credentials and cleartext transmission of sensitive information.
Hitachi Energy FACTS Control Platform (FCP)
CISA Advisories | CVSS 9.9 | CVE-2024-4872, CVE-2024-3980, CVE-2024-3982, CVE-2024-7940, CVE-2024-7941
โ Why Should I Care?
Yes, if you run Hitachi Energy FACTS Control Platform (FCP) versions 3.4.0 to 4.1.1 with GWS component: these vulnerabilities can allow an attacker to compromise confidentiality, integrity, and availability of your system.
๐ฏ Affected versions: 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1
Not affected: Versions without GWS component
๐ญ In plain English:
These vulnerabilities allow an attacker with valid credentials to inject malicious code into your system, potentially giving them control over critical files and operations. For example, an attacker could modify system files to disrupt operations or steal sensitive data.
๐ง Prerequisites:
- Valid credentials
- Access to the FACTS Control system with GWS component
โฑ Urgency: High urgency due to the critical impact on system confidentiality, integrity, and availability.
๐ก Context: The root cause includes improper validation of user inputs and lack of proper authentication mechanisms.
Mitsubishi Electric GX Works3 and Motion Control Settings
CISA Advisories | CVSS 8.8 | CVE-2026-15688
โ Why Should I Care?
Yes, if you run any version of Mitsubishi Electric GX Works3 or Motion Control Settings: this vulnerability allows local attackers to bypass authentication and modify control programs.
๐ฏ Affected versions: all/*
๐ญ In plain English:
This vulnerability means that someone with access to your system can log in even if they don't have the correct password, and then they can change, delete, or destroy control programs. For example, an attacker could alter the settings of industrial machinery, potentially causing it to malfunction or stop working.
๐ง Prerequisites:
- Local access to the system
- Invalid block password
โฑ Urgency: High urgency due to the high CVSS score and the potential for local attackers to bypass authentication and modify critical control programs.
โ Fixed in: 1.096A, 1.070Y
๐ก Context: The root cause is an incorrect implementation of the authentication algorithm.
Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)
CISA Advisories | CVE-2026-13584
โ Why Should I Care?
Yes, if you run any version of the affected Mitsubishi Electric MELSEC MX Controller models or related modules: this vulnerability could allow an attacker to disrupt your control systems and cause a denial-of-service condition.
๐ฏ Affected versions: all versions of the affected Mitsubishi Electric MELSEC MX Controller models and related modules
๐ญ In plain English:
An attacker can send special packets to disrupt the communication between your control systems, causing them to malfunction or stop working. For example, an attacker could cause a factory's machinery to stop operating correctly, leading to production downtime.
๐ง Prerequisites:
- Access to the same network segment as the affected product
- Ability to send specially crafted packets under specific timing conditions
โฑ Urgency: High urgency due to the potential for operational disruption and denial-of-service conditions in critical control systems.
๐ก Context: The root cause is a flaw in the CC-Link IE TSN Communication Protocol that allows for tampering with communication data under specific timing conditions.
Why Should I Care? ๐ต On the Radar (23)
- Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks (The Hacker News) โ Cisco has identified a critical flaw in ISE and ISE-PIC that allows attackers to bypass authentication and gain unauthorized access. This could lead to full control of the device, including root privileges.
- Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files (The Hacker News) โ A critical flaw in Docker Sandboxes on macOS allows malicious code inside a sandbox to access and modify files on the host system. This affects versions 0.28.0 to 0.41.9 and was fixed in version 0.42.0.
- Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root (The Hacker News) โ A severe flaw in Check Point's Security Management and Log Servers lets attackers without login credentials execute root-level commands. This can compromise your entire security infrastructure. For example, an attacker could change firewall policies or steal sensitive data.
- Brevo supply-chain attack injected ClickFix scripts on customer sites (BleepingComputer) โ Brevo, a digital marketing company, was hit by a supply-chain attack where hackers injected malicious scripts into their websites and customer sites. This could have exposed up to 100,000 websites to malware.
- Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records (The Hacker News) โ A major security breach at Gyazo exposed millions of user records and image metadata, potentially allowing unauthorized access to private images. This could affect your personal data and privacy.
- China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America (The Hacker News) โ A Chinese state-sponsored group, FamousSparrow, is using a new backdoor called SparroWocky to target governmental and high-profile entities in Latin America. This backdoor can execute files, exfiltrate data, and evade detection, posing a significant threat to cybersecurity.
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone (The Hacker News) โ A critical flaw in Unbound DNS resolver versions before 1.26.1 allows attackers to execute remote code by controlling a malicious DNS zone. This could lead to system compromise or denial of service.
- Cisco warns of max severity ISE zero-day exploited in attacks (BleepingComputer) โ Cisco has identified a critical vulnerability in its ISE and ISE-PIC products that allows attackers to bypass authentication and gain unauthorized access. This is a high-severity issue that is currently being exploited in the wild.
- New RatHat Android malware uses AI to automate device control (BleepingComputer) โ RatHat is a new Android malware that uses AI to navigate and control compromised devices, stealing sensitive information like passwords and PINs. It's distributed through malvertising, SMS, and phishing sites, and it's particularly dangerous because it can thwart removal attempts and adapt to different interfaces.
- BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS (The Hacker News) โ The BIND 9 update fixes 14 security flaws, including one that allows attackers to crash DNS-over-HTTPS servers with a single invalid request. This could disrupt your DNS services and lead to downtime.
- Windows 11 24H2 Home and Pro reach end of support in October (BleepingComputer) โ Windows 11 24H2 Home and Pro will stop receiving updates in October, leaving devices vulnerable to security threats. Users should upgrade to Windows 11 25H2 to continue receiving security updates.
- Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords (The Hacker News) โ Attribution of Iran-linked Handala Hack to HEAVYGRAM Telegram backdoor.
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories (The Hacker News) โ General threat landscape overview.
- Run open weight models on Amazon Bedrock in AWS European Sovereign Cloud (AWS Security Blog) โ General availability announcement for running open weight models on AWS Bedrock in the European Sovereign Cloud.
- Inside the Modern SOC: Defending the Cross-Environment Pivot (Palo Alto Unit 42) โ Educational content on cross-environment security operations.
โช 77 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV