CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)35
Última detecciónhace 2 d
Monitorizado porintelligence scouter
29signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft118Cisco53Google43GitHub35Apple32Adobe24Check Point19ServiceNow18Siemens17Ivanti

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate2d

    Hitachi Energy APM Edge Product

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA ICS Advisories · Hitachi Energy Product Version: APM Edge versions 6 · GitHubReview signal
  2. Action RequiredImmediate
All35Action Required29Exploited & KEV3Critical Vulns4Cloud & Identity2

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Pro para abrir el feed completo, histórico ampliado y el catálogo KEV.

INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

Hitachi Energy APM Edge Product

View CSAF Summary Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy APM Edge Product are affected: APM Edge vers:APM_Edge/<=6.10 (CVE-2026-43284, CVE-2026-43500) CVSS Vendor Equipment Vulnerabilities v3 8.8 Hitachi Energy Hitachi Energy APM Edge Product Write-what-where Condition, Out-of-bounds Write Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-43284 CWE-123: Write-what-where Condition A vulnerability exists in the IPsec ESP subsystem (esp4, esp6) of the Linux kernel used in APM Edge that allows a local unprivileged user to escalate privileges to root. The flaw exists in how the kernel handles memory pages when processing ESP encrypted network packets. An attacker can craft a packet that causes the kernel to decrypt data directly into memory pages it does not own, including the cached copies of privileged operating system binaries. When one of those binaries is executed, the attacker's injected code runs with root privileges. In APM Edge, the vulnerable kernel modules (esp4, esp6) can be loaded by any local user and exploited. View CVE Details Affected Products Hitachi Energy APM Edge Product Vendor: Hitachi Energy Product Version: APM Edge versions 6.10 and prior Product Status: known_affected Remediations Mitigation Disable the esp4 and esp6 modules [2] Relevant CWE: CWE-123 Write-what-where Condition Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVE-2026-43500 CWE-787: Out-of-bounds Write A vulnerability exists in the RxRPC protocol im CVEs: CVE-2026-43284, CVE-2026-43500. CISA KEV/exploitation signal detected. Vendors: Hitachi Energy Product Version: APM Edge versions 6, GitHub, Linux, Siemens. DORA relevance: medium.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

3signals
Explotados & KEV
4signals
Vulns Críticas
Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity2
16
PHP15
SonicWall15
Fortinet14
SAP12
2d

Siemens Simcenter Femap

Explotación activa confirmada. Riesgo material para entornos expuestos.

CISA ICS Advisories · Siemens Product Version: Simcenter Femap < V2606 · GitHubReview signal
  • Action RequiredImmediate2d

    Haiwell IoT Cloud HMI Gateway

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA ICS Advisories · Haiwell Product Version: Haiwell Haiwell IoT Cloud HMI Gateway: 3 · GitHubReview signal
  • Action RequiredImmediate2d

    Siemens Siveillance Video

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA All Alerts · Siemens Product Version: Siveillance Video V2023 R3 < V23 · GitHubReview signal
  • Action RequiredImmediate2d

    Siemens Parasolid

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA All Alerts · Siemens Product Version: Parasolid V38 · GitHubReview signal
  • Action RequiredImmediate2d

    Siemens Solid Edge

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA All Alerts · Siemens Product Version: Solid Edge SE2025 < V225 · GitHubReview signal
  • Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-43284, CVE-2026-43500 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:Hitachi Energy Product Version: APM Edge versions 6GitHubLinuxSiemensCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 12:00
    Actualizado
    13 ago 2026, 18:02
    Detectado
    13 ago 2026, 18:02
    Fuente
    CISA ICS Advisories
    Referencia técnica
    NVD · CVE-2026-43284
    CISA ICS Advisories
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA ICS Advisories authority (+12) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

    Siemens Simcenter Femap

    View CSAF Summary Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version. The following versions of Siemens Simcenter Femap are affected: Simcenter Femap vers:intdot/<2606.0001 (CVE-2026-59700, CVE-2026-59701) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens Simcenter Femap Out-of-bounds Read Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-59700 The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Simcenter Femap Vendor: Siemens Product Version: Simcenter Femap < V2606.0001 Product Status: known_affected Remediations Vendor fix Update to V2606.0001 or later version https://support.sw.siemens.com/product/275652363/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2026-59701 The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Simcenter Femap Vendor: Siemens Product Version: Simcenter Femap < V2606.0001 Product Status: known_affected Remediations Vendor fix Update to V2606.0001 or later version https://support.sw.siemens.com/product/275652363/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version CVEs: CVE-2026-59700, CVE-2026-59701. CISA KEV/exploitation signal detected. Vendors: Siemens Product Version: Simcenter Femap < V2606, GitHub, Siemens. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-59700, CVE-2026-59701 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:Siemens Product Version: Simcenter Femap < V2606GitHubSiemensCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 12:00
    Actualizado
    13 ago 2026, 18:02
    Detectado
    13 ago 2026, 18:02
    Fuente
    CISA ICS Advisories
    Referencia técnica
    NVD · CVE-2026-59700
    CISA ICS Advisories
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA ICS Advisories authority (+12) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

    Haiwell IoT Cloud HMI Gateway

    View CSAF Summary Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected: Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188) CVSS Vendor Equipment Vulnerabilities v3 10 Haiwell Haiwell IoT Cloud HMI Gateway Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Energy, Critical Manufacturing, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-19188 A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges View CVE Details Affected Products Haiwell IoT Cloud HMI Gateway Vendor: Haiwell Product Version: Haiwell Haiwell IoT Cloud HMI Gateway: 3.40.1.12 Product Status: known_affected Remediations Mitigation Haiwell has addressed the issue in patch version number Scada-v3.50.1.19, which is available for download on their website: https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361 https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361 Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 10 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Acknowledgments Fiqram Akmal reported this vulnerability to CISA Legal Notice and Terms of Use This CVEs: CVE-2026-19188. CISA KEV/exploitation signal detected. Vendors: Haiwell Product Version: Haiwell Haiwell IoT Cloud HMI Gateway: 3, GitHub, Siemens, PHP. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-19188 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:Haiwell Product Version: Haiwell Haiwell IoT Cloud HMI Gateway: 3GitHubSiemensPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 12:00
    Actualizado
    13 ago 2026, 18:02
    Detectado
    13 ago 2026, 18:02
    Fuente
    CISA ICS Advisories
    Referencia técnica
    NVD · CVE-2026-19188
    CISA ICS Advisories
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA ICS Advisories authority (+12) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

    Siemens Siveillance Video

    View CSAF Summary Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Siveillance Video are affected: Siveillance Video V2023 R3 vers:intdot/<23.3.27 (CVE-2026-3014) Siveillance Video V2024 R1 vers:intdot/<24.1.16 (CVE-2026-3014) Siveillance Video V2025 vers:intdot/<25.1.15 (CVE-2026-3014) CVSS Vendor Equipment Vulnerabilities v3 9.1 Siemens Siemens Siveillance Video Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Critical Manufacturing, Communications, Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-3014 Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service. View CVE Details Affected Products Siemens Siveillance Video Vendor: Siemens Product Version: Siveillance Video V2023 R3 < V23.3.27, Siveillance Video V2024 R1 < V24.1.16, Siveillance Video V2025 < V25.1.15 Product Status: known_affected Remediations Vendor fix Update to V23.3 HotfixRev27 or later version https://support.industry.siemens.com/cs/ww/en/view/109827783/ Vendor fix Update to V24.1 HotfixRev16 or later version https://support.industry.siemens.com/cs/ww/en/view/109976123/ Vendor fix Update to V25.1 HotfixRev15 or later version https://support.industry.siemens.com/cs/ww/en/view/109988670/ Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV CVEs: CVE-2026-3014. CISA KEV/exploitation signal detected. Vendors: Siemens Product Version: Siveillance Video V2023 R3 < V23, GitHub, Siemens. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-3014 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:Siemens Product Version: Siveillance Video V2023 R3 < V23GitHubSiemensCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 12:00
    Actualizado
    13 ago 2026, 18:01
    Detectado
    13 ago 2026, 18:01
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-3014
    CISA All Alerts
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

    Siemens Parasolid

    View CSAF Summary Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Parasolid are affected: Parasolid V38.0 vers:intdot/<38.0.235 (CVE-2026-64629) Parasolid V38.1 vers:intdot/<38.1.230 (CVE-2026-64629) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens Parasolid Out-of-bounds Read Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-64629 The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Parasolid Vendor: Siemens Product Version: Parasolid V38.0 < V38.0.235, Parasolid V38.1 < V38.1.230 Product Status: known_affected Remediations Vendor fix Update to V38.0.235 or later version https://support.sw.siemens.com/product/258316782/ Vendor fix Update to V38.1.230 or later version https://support.sw.siemens.com/product/258316782/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Acknowledgments Siemens ProductCERT reported this vulnerability to CISA. General Recommendations As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial CVEs: CVE-2026-64629. CISA KEV/exploitation signal detected. Vendors: Siemens Product Version: Parasolid V38, GitHub, Siemens. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-64629 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:Siemens Product Version: Parasolid V38GitHubSiemensCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 12:00
    Actualizado
    13 ago 2026, 18:01
    Detectado
    13 ago 2026, 18:01
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-64629
    CISA All Alerts
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

    Siemens Solid Edge

    View CSAF Summary Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Solid Edge are affected: Solid Edge SE2025 vers:intdot/<225.0.15 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064) Solid Edge SE2026 vers:intdot/<226.0.7 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens Solid Edge Out-of-bounds Read, Out-of-bounds Write, Use After Free Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-50058 The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Solid Edge Vendor: Siemens Product Version: Solid Edge SE2025 < V225.0.15, Solid Edge SE2026 < V226.0.7 Product Status: known_affected Remediations Vendor fix Update to V225.0 Update 15 or later version https://support.sw.siemens.com/product/246738425/ Vendor fix Update to V226.0 Update 7 or later version https://support.sw.siemens.com/product/246738425/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2026-50059 The affected applications contains an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context o CVEs: CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062. CISA KEV/exploitation signal detected. Vendors: Siemens Product Version: Solid Edge SE2025 < V225, GitHub, Siemens. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-50058, CVE-2026-50059, CVE-2026-50060 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:Siemens Product Version: Solid Edge SE2025 < V225GitHubSiemensCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 12:00
    Actualizado
    13 ago 2026, 17:00
    Detectado
    13 ago 2026, 17:00
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-50058
    CISA All Alerts
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

    ANDRITZ HIPASE-250 and 250 SCALA

    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations. The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected: HIPASE-250 <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313) 250 SCALA <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313) CVSS Vendor Equipment Vulnerabilities v3 8.1 ANDRITZ ANDRITZ HIPASE-250 and 250 SCALA Storing Passwords in a Recoverable Format, Missing Authentication for Critical Function, Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Austria Vulnerabilities Expand All + CVE-2026-65309 ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords. View CVE Details Affected Products ANDRITZ HIPASE-250 and 250 SCALA Vendor: ANDRITZ Product Version: ANDRITZ HIPASE-250: <=7.20, ANDRITZ 250 SCALA: <=7.20 Product Status: known_affected Remediations Vendor fix ANDRITZ has addressed these issues in version V8.00.00 (released 2024-12) and in version V8.15.00 (released 2026-07) and encourages users to keep their systems updated to the latest version (currently HIPASE-250 Version V8.15.00). For more information, users can contact ANDRITZ at the following website: https://www.andritz.com/group-en/contact https://www.andritz.com/group-en/contact Relevant CWE: CWE-257 Storing Passwords in a Recoverable Format Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-65310 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affec CVEs: CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313. CISA KEV/exploitation signal detected. Vendors: ANDRITZ Product Version: ANDRITZ HIPASE-250: <=7, GitHub, Siemens. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-65309, CVE-2026-65310, CVE-2026-65311 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:ANDRITZ Product Version: ANDRITZ HIPASE-250: <=7GitHubSiemensCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 12:00
    Actualizado
    13 ago 2026, 17:00
    Detectado
    13 ago 2026, 17:00
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-65309
    CISA All Alerts
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

    Siemens LOGO! Soft Comfort

    View CSAF Summary Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version. The following versions of Siemens LOGO! Soft Comfort are affected: LOGO! Soft Comfort vers:intdot/<9 (CVE-2026-57262, CVE-2026-57263) CVSS Vendor Equipment Vulnerabilities v3 6.8 Siemens Siemens LOGO! Soft Comfort Use of Hard-coded Cryptographic Key, Use of a One-Way Hash without a Salt Background Critical Infrastructure Sectors: Commercial Facilities, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-57262 Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password. View CVE Details Affected Products Siemens LOGO! Soft Comfort Vendor: Siemens Product Version: LOGO! Soft Comfort < V9 Product Status: known_affected Remediations Vendor fix Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present. Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N CVE-2026-57263 The CVEs: CVE-2026-57262, CVE-2026-57263. CISA KEV/exploitation signal detected. Vendors: Siemens Product Version: LOGO! Soft Comfort < V9 Product Status: known_affected Remediations Vendor fix Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present, GitHub, Siemens. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-57262, CVE-2026-57263 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:Siemens Product Version: LOGO! Soft Comfort < V9 Product Status: known_affected Remediations Vendor fix Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain presentGitHubSiemensCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 12:00
    Actualizado
    13 ago 2026, 17:00
    Detectado
    13 ago 2026, 17:00
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-57262
    CISA All Alerts
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <7d (+3 cap)
    hace 2 días