Threats Tagged 'cve-2026-34223'
View all threats tagged with 'cve-2026-34223'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-34223'
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family… (CVE-2026-34223)CVE-2026-34223 0 A high-severity vulnerability (CVE-2026-34223) affects all versions of multiple Desigo CC client applications, including ClickOnce Client V6 and V7, family V8 and V9, Flex Client V6 and V7, and Installed Client V6 and V7. The flaw allows client code execution due to insufficient input validation of scripts embedded in user-defined graphics documents. An attacker who crafts a malicious graphics document and convinces a user with sufficient privileges to open it can execute arbitrary commands on the client system, potentially writing files and enabling system compromise and lateral movement. Join the discussion | GCVE Database | 09/08/2026, 09:35:38 UTC Added: 09/08/2026, 12:55:05 UTC |
CVE-2026-34223: CWE-94: Improper Control of Generation of Code ('Code Injection') in Siemens Desigo CC ClickOnce Client V6CVE-2026-34223 0 A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All versions), Desigo CC Installed Client V7 (All versions). The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization. Join the discussion | CVE Database V5 | 09/08/2026, 08:11:17 UTC Added: 09/08/2026, 08:37:40 UTC |
Showing 1 to 2 of 2 results