Skip to main content

Threats Tagged 'cisa'

View all threats tagged with 'cisa'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cisa

Threats Tagged 'cisa'

Click on any threat for detailed analysis and mitigation recommendations

Redis has a use-after-free vulnerability in the tlsProcessPendingData() function, which manages the TLS pending-data list when TLS support is enabled. This flaw could allow a remote, unauthenticated attacker to execute arbitrary commands with the privileges of the Redis server. The vulnerability is identified as CVE-2026-81934 and is associated with CWE-416 (use-after-free). No specific affected versions or patches are currently provided.

Join the discussion

AzeoTech DAQFactory versions 21.1 and earlier contain a type confusion vulnerability (CWE-843) that can be exploited via specially crafted .ctl files to achieve code execution. This vulnerability has a high severity with a CVSS score of 8.4. There are no known exploits in the wild and no patches or fixes have been indicated in the available data.

Join the discussion

CVE-2026-8806 is a high-severity vulnerability in all versions of the Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module. It allows a remote attacker to cause a denial-of-service (DoS) by flooding the Ethernet port with a large number of packets in a short time. This overload prevents the module's internal anomaly-detection processing, leading to a communication function failure.

Join the discussion

CVE-2026-8805 is an integer overflow vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module FX5-EIP versions 1.000 and earlier. A remote attacker can exploit this by rapidly establishing many TCP connections, causing a denial-of-service (DoS) condition due to improper memory access triggered by internal connection management inconsistencies.

Join the discussion
0

An improper input validation vulnerability (CWE-552) exists in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras. This flaw may allow a remote, unauthenticated attacker to execute arbitrary code by sending a specially crafted web request. The vulnerability has a critical CVSS score of 9.8, indicating high impact on confidentiality, integrity, and availability. No patch or official remediation information is currently provided by the vendor. The affected versions include all versions of the specified camera models. There are no known exploits in the wild at this time.

Join the discussion

CVE-2026-50034 affects the Apollo Pharmacy Blood Glucose Monitoring System (Model No. APG-01 BT). An attacker within Bluetooth Low Energy (BLE) communication range can passively intercept wireless traffic and obtain sensitive health-related information, specifically glucose measurement values. This vulnerability is classified under CWE-319, indicating the transmission of sensitive information in an unprotected manner. The CVSS 3.1 base score is 6.5, reflecting a medium severity level. No patches or fixes are currently documented for this vulnerability. The device is not a cloud service, so remediation depends on vendor updates or device replacement.

Join the discussion
0

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.

Join the discussion

A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized actor to execute privileged operations, including user/role management and other administrative actions.

Join the discussion

CVE-2026-42947 is a high-severity authorization bypass vulnerability in the Naxclow Smart Doorbell X3. The flaw exists in the onboarding workflow, allowing an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. The affected endpoints validate request signatures but do not verify legitimate ownership, enabling attackers with any account to take over devices without user interaction while the device remains online and unaware.

Join the discussion

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carrying real-time telemetry for the entire global Yarbo robot fleet. They allow both wildcard subscription to all robot telemetry topics and publishing to any robot's command topic using only the robot's serial number.

Join the discussion

Showing 1 to 10 of 12 results

Filters:Tag: cisa
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses