Why Should I Care? โ€” 2026-09-23 | ๐Ÿ”ด 5 HIGH ยท ๐ŸŸก 3 MEDIUM ยท ๐Ÿ”ต 27 RADAR ยท โšช 69 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-23

35 vendor intel items scanned  |  ๐Ÿ”ด 5 HIGH  |  ๐ŸŸก 3 MEDIUM  |  ๐Ÿ”ต 27 RADAR  |  โšช 69 FILTERED

๐Ÿ”ด Critical โ€” action required:

  1. CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127) โ€” Yes, if you run any affected versions of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM: these vulnerabilities are actively exploited and pose significant risks.
  2. Siemens SIPLUS and SIMATIC Products (CVE-2026-31431) โ€” Yes, if you run any version of SIMATIC AX Runtime Core Linux Common Debian, SIMATIC AX Runtime Core Linux Common Debian arm64, SIMATIC AX Runtime Core Linux Platform Container Common Debian Development, SIMATIC AX Runtime Core Linux VMWare Development, or SIMATIC CN 4100 below version 6.0: you are vulnerable to the 'Copy Fail' vulnerability.
  3. lwIP TCP/IP Stack MQTT Client Application (CVE-2026-87121) โ€” Yes, if you run MQTT Client Application versions >=2.0.1 and <=2.2.1: an attacker could gain full code execution on your device.
  4. Siemens Siveillance Control (CVE-2026-50093) โ€” Yes, if you run Siveillance Control or Siveillance Control Pro versions below 3.0.12.2173, 4.0.9.2178, 3.0.22.2177, or 4.0.11.2177: An attacker can upload files to gain root access, fully compromising your system.
  5. Siemens Industrial Edge Management (CVE-2026-18963) โ€” Yes, if you run Siemens Industrial Edge Management Cloud, Pro V1 >= 1.14.9 < 1.15.20, Pro V2 >= 2.2.0 < 2.2.2, or Virtual >= 2.6.0 < 2.9.1: An attacker can reset user credentials and take over accounts without email verification.

Everything else can wait.

๐ŸŸก Medium โ€” review when time permits:

  1. Siemens Desigo CC family โ€” Yes, if you run Siemens Desigo CC family V6 or V7: this vulnerability allows attackers to execute arbitrary code on your client devices through specially crafted graphics documents.
  2. lwIP (Lightweight IP) โ€” Yes, if you run lwIP API versions >=2.0.1 and <=2.2.1: this vulnerability could crash your system, cause a DoS, or allow an attacker to execute arbitrary code.
  3. OpenPLC Runtime v3 โ€” Yes, if you run OpenPLC Runtime v3: this vulnerability allows attackers to hijack session cookies and control the PLC, impacting critical infrastructure.

๐Ÿ”ต 15 items on the radar โ€” see below โ†“


Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now


CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA Advisories [CISA KEV] | CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127

โ“ Why Should I Care?
Yes, if you run any affected versions of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM: these vulnerabilities are actively exploited and pose significant risks.

๐ŸŽฏ Affected versions: Check Point Multiple Products: all versions; Arista VeloCloud Orchestrator: all versions; F5 BIG-IP APM: all versions

๐ŸŽญ In plain English:
These vulnerabilities allow attackers to either bypass security checks, access sensitive files, or crash systems. For example, an attacker could exploit the Check Point vulnerability to bypass security checks and gain unauthorized access to your network.

๐Ÿ”ง Prerequisites:

  • Running an affected version of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM

โฑ Urgency: High urgency due to active exploitation and significant risk to the federal enterprise.

๐Ÿ’ก Context: The root cause involves improper validation and handling of input or certificates, allowing attackers to exploit these vulnerabilities.


Siemens SIPLUS and SIMATIC Products

CISA Advisories [CISA KEV] | CVE-2026-31431

โ“ Why Should I Care?
Yes, if you run any version of SIMATIC AX Runtime Core Linux Common Debian, SIMATIC AX Runtime Core Linux Common Debian arm64, SIMATIC AX Runtime Core Linux Platform Container Common Debian Development, SIMATIC AX Runtime Core Linux VMWare Development, or SIMATIC CN 4100 below version 6.0: you are vulnerable to the 'Copy Fail' vulnerability.

๐ŸŽฏ Affected versions: SIMATIC AX Runtime Core Linux Common Debian vers:all/*, SIMATIC AX Runtime Core Linux Common Debian arm64 vers:all/*, SIMATIC AX Runtime Core Linux Platform Container Common Debian Development vers:all/*, SIMATIC AX Runtime Core Linux VMWare Development vers:all/*, SIMATIC CN 4100 vers:intdot/<6.0

๐ŸŽญ In plain English:
The 'Copy Fail' vulnerability means that an attacker could potentially copy sensitive data from your system without your knowledge. For example, an attacker could copy configuration files or other sensitive data from your SIMATIC devices, which could then be used to further compromise your system or steal sensitive information.

๐Ÿ”ง Prerequisites:

  • The attacker must have network access to the affected SIMATIC devices.

โฑ Urgency: High urgency due to the potential for sensitive data exfiltration.

โœ… Fixed in: 6.0 and above for SIMATIC CN 4100

๐Ÿ’ก Context: The root cause is a flaw in the data handling mechanisms that allows for unauthorized data copying.


lwIP TCP/IP Stack MQTT Client Application

CISA Advisories | CVSS 9.8 | CVE-2026-87121

โ“ Why Should I Care?
Yes, if you run MQTT Client Application versions >=2.0.1 and <=2.2.1: an attacker could gain full code execution on your device.

๐ŸŽฏ Affected versions: >=2.0.1 and <=2.2.1

๐ŸŽญ In plain English:
This vulnerability allows an attacker to write data outside the intended memory area, potentially giving them full control over your device. For example, an attacker could remotely execute malicious code, take over your device, and perform actions like stealing data or disrupting operations.

๐Ÿ”ง Prerequisites:

  • Running MQTT Client Application versions >=2.0.1 and <=2.2.1

โฑ Urgency: High urgency due to the critical nature of the vulnerability and the potential for full code execution.

โœ… Fixed in: f89407ea711879c04d91c92b35d67be78bbaf0f1

๐Ÿ’ก Context: The root cause is an out-of-bounds write vulnerability in the lwIP TCP/IP Stack MQTT Client Application.


Siemens Siveillance Control

CISA Advisories | CVSS 9 | CVE-2026-50093

โ“ Why Should I Care?
Yes, if you run Siveillance Control or Siveillance Control Pro versions below 3.0.12.2173, 4.0.9.2178, 3.0.22.2177, or 4.0.11.2177: An attacker can upload files to gain root access, fully compromising your system.

๐ŸŽฏ Affected versions: Siveillance Control Pro V3.0 < V3.0.12.2173, Siveillance Control Pro V4.0 < V4.0.9.2178, Siveillance Control V3.0 < V3.0.22.2177, Siveillance Control V4.0 < V4.0.11.2177

๐ŸŽญ In plain English:
This vulnerability lets attackers upload any file they want to your server, which can give them full control over your system. For example, an attacker could upload a malicious script that allows them to take over your entire server and steal sensitive data.

๐Ÿ”ง Prerequisites:

  • Access to the OIS web module
  • Versions below the patched versions

โฑ Urgency: High urgency due to the potential for full system compromise and unauthorized access.

โœ… Fixed in: 3.0.12.2173, 4.0.9.2178, 3.0.22.2177, 4.0.11.2177

๐Ÿ’ก Context: The root cause is an unrestricted file upload feature that does not properly validate the type or content of uploaded files.


Siemens Industrial Edge Management

CISA Advisories | CVSS 9.1 | CVE-2026-18963

โ“ Why Should I Care?
Yes, if you run Siemens Industrial Edge Management Cloud, Pro V1 >= 1.14.9 < 1.15.20, Pro V2 >= 2.2.0 < 2.2.2, or Virtual >= 2.6.0 < 2.9.1: An attacker can reset user credentials and take over accounts without email verification.

๐ŸŽฏ Affected versions: Industrial Edge Management Cloud: all, Pro V1: >= 1.14.9 < 1.15.20, Pro V2: >= 2.2.0 < 2.2.2, Virtual: >= 2.6.0 < 2.9.1

๐ŸŽญ In plain English:
This vulnerability means an attacker can reset user passwords and take over accounts without needing to verify via email. For example, an attacker could log in as an admin and change critical settings or steal sensitive data.

๐Ÿ”ง Prerequisites:

  • Unauthenticated access to the system
  • Access to the password reset functionality

โฑ Urgency: High urgency due to the risk of full account takeover by unauthenticated attackers.

โœ… Fixed in: 1.15.20, 2.2.2, 2.9.1

๐Ÿ’ก Context: The root cause is a flaw in the reset-credentials flow of the keycloak-services component, allowing bypass of email verification.


Why Should I Care? ๐ŸŸก MEDIUM (3)


Siemens Desigo CC family

CISA Advisories | CVSS 8.2 | CVE-2026-34223

โ“ Why Should I Care?
Yes, if you run Siemens Desigo CC family V6 or V7: this vulnerability allows attackers to execute arbitrary code on your client devices through specially crafted graphics documents.

๐ŸŽฏ Affected versions: Desigo CC family V6 vers:all/*, Desigo CC family V7 vers:all/*

๐ŸŽญ In plain English:
This vulnerability means that if you open a specially crafted graphics document, an attacker can run any code they want on your computer, potentially taking control of it. For example, an attacker could use this to install malware or gain access to other parts of your network.

๐Ÿ”ง Prerequisites:

  • User must open a maliciously crafted graphics document
  • User must have sufficient privileges to display the document

โฑ Urgency: High urgency due to the potential for full client system compromise and lateral movement within the network.

๐Ÿ’ก Context: The root cause is insufficient input validation when handling scripts embedded within user-defined graphics documents.


lwIP (Lightweight IP)

CISA Advisories | CVSS 8.8 | CVE-2026-91018

โ“ Why Should I Care?
Yes, if you run lwIP API versions >=2.0.1 and <=2.2.1: this vulnerability could crash your system, cause a DoS, or allow an attacker to execute arbitrary code.

๐ŸŽฏ Affected versions: API >=2.0.1 and <=2.2.1

๐ŸŽญ In plain English:
This vulnerability allows an attacker to crash your system, make it unresponsive, or take control of it. For example, an attacker could send a specially crafted packet to your system, causing it to crash or allowing them to run any code they want.

๐Ÿ”ง Prerequisites:

  • Running affected lwIP versions
  • Network access to the system

โฑ Urgency: High urgency due to the potential for remote code execution and system crashes.

โœ… Fixed in: f873b6295933e4149a2132adf3e9a2d2a676a5ec

๐Ÿ’ก Context: The root cause is a double free vulnerability in lwIP, where memory is freed twice, leading to undefined behavior.


OpenPLC Runtime v3

CISA Advisories | CVSS 6.1 | CVE-2026-88020

โ“ Why Should I Care?
Yes, if you run OpenPLC Runtime v3: this vulnerability allows attackers to hijack session cookies and control the PLC, impacting critical infrastructure.

๐ŸŽฏ Affected versions: OpenPLC 3

๐ŸŽญ In plain English:
This vulnerability means an attacker could steal your session cookies and pretend to be you, allowing them to control the PLC and the processes it manages. For example, they could change the settings of a manufacturing plant's machinery, potentially causing malfunctions or safety issues.

๐Ÿ”ง Prerequisites:

  • Access to the web interface
  • No proper input validation

โฑ Urgency: High urgency due to the potential for attackers to control critical infrastructure processes.

โœ… Fixed in: OpenPLC v4

๐Ÿ’ก Context: The root cause is improper neutralization of input during web page generation, leading to cross-site scripting.


Why Should I Care? ๐Ÿ”ต On the Radar (27)


โšช 69 low-priority items filtered.


๐Ÿฆ… Aggregated and triaged by Donna AI  |  Sources: 8 vendor feeds  |  CISA KEV

Read more

Why Should I Care? โ€” 2026-09-24 | ๐Ÿ”ด 0 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 27 RADAR ยท โšช 69 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-24 27 vendor intel items scanned ย |ย  ๐Ÿ”ด 0 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 27 RADAR ย |ย  โšช 69 FILTERED โœ… No critical items today. Everything else can wait. ๐Ÿ”ต 15 items on the radar โ€” see below โ†“ Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now No HIGH priority items in the last 24h. Why Should I Care? ๐ŸŸก MEDIUM

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-22 | ๐Ÿ”ด 1 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 17 RADAR ยท โšช 66 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-22 18 vendor intel items scanned ย |ย  ๐Ÿ”ด 1 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 17 RADAR ย |ย  โšช 66 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-7273) โ€” Yes, if you run Zyxel GS1900 Series Switches: This vulnerability can allow attackers to take full control of your switch. Everything else

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-21 | ๐Ÿ”ด 23 HIGH ยท ๐ŸŸก 32 MEDIUM ยท ๐Ÿ”ต 209 RADAR ยท โšช 73 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-21 264 vendor intel items scanned ย |ย  ๐Ÿ”ด 23 HIGH ย |ย  ๐ŸŸก 32 MEDIUM ย |ย  ๐Ÿ”ต 209 RADAR ย |ย  โšช 73 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-76461) โ€” Yes, if you run Cisco Secure Email Gateway versions 12.0.0 - 12.0.4: SQL injection vulnerability, actively exploited in

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-20 | ๐Ÿ”ด 0 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 12 RADAR ยท โšช 80 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-20 12 vendor intel items scanned ย |ย  ๐Ÿ”ด 0 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 12 RADAR ย |ย  โšช 80 FILTERED โœ… No critical items today. Everything else can wait. ๐Ÿ”ต 12 items on the radar โ€” see below โ†“ Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now No HIGH priority items in the last 24h. Why Should I Care? ๐ŸŸก MEDIUM

By Josip Sokolovic