Overview
- CODESYS
- CODESYS EtherNetIP
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
#OT #Advisory VDE-2026-040
CODESYS EtherNetIP - Improper timeout handling
CODESYS EtherNet/IP is an add‑on for the CODESYS Development System that provides a fully integrated EtherNet/IP protocol stack along with diagnostic capabilities. A flaw in the EtherNet/IP adapter protocol stack library results in a vulnerability within the generated application code. When an EtherNet/IP adapter is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
#CVE CVE-2026-35225
https://certvde.com/en/advisories/vde-2026-040/
#oCSAF
#CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-04_vde-2026-040.json
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
#OT #Advisory VDE-2026-029
METTLER TOLEDO: OpenSSL vulnerability in MX and MR balances
MX/MR firmware V2.0.0 or earlier is affected by the OpenSSL vulnerability CVE-2025-15467.
#CVE CVE-2025-15467
https://certvde.com/en/advisories/vde-2026-029/
#oCSAF
#CSAF https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-029.json
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
"ERB patches deserialization guard bypass enabling code execution"
Published 21 Apr 2026
Source: Ruby-lang.org Security Advisory
CVE-2026-41316
https://justappsec.com/news/2026-04-erb-deserialization-guard-bypass
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
- coreruleset
- coreruleset
Description
Statistics
- 1 Post
Overview
- luanti-org
- luanti
Description
Statistics
- 1 Post
Fediverse
🔴 CVE-2026-41196: luanti 5.0.0 – 5.15.1 has a CRITICAL code injection vuln (CVSS 9.0). Malicious mods can break Lua sandbox with LuaJIT, gaining full filesystem access. Patch: upgrade to 5.15.2 or mitigate via getfenv = nil. https://radar.offseq.com/threat/cve-2026-41196-cwe-94-improper-control-of-generati-70ec6155 #OffSeq #CVE202641196 #vuln
Overview
Description
Statistics
- 1 Post
Overview
- Beghelli
- SicuroWeb (Sicuro24)
Description
Statistics
- 1 Post
Fediverse
🛑 CVE-2026-41468: Beghelli SicuroWeb (Sicuro24) uses unmaintained AngularJS 1.5.2, allowing network-adjacent attackers to hijack sessions via MITM and template injection. Enforce HTTPS, monitor activity. No patch yet. More: https://radar.offseq.com/threat/cve-2026-41468-cwe-1104-use-of-unmaintained-third--1563ff90 #OffSeq #CVE202641468 #infosec
Overview
- langflow-ai
- langflow
Description
Statistics
- 1 Post
Bluesky
Overview
- BorG Technology Corporation
- Borg SPM 2007
Description
Statistics
- 1 Post
Fediverse
🚨 CRITICAL SQL Injection (CVE-2026-6887) in BorG SPM 2007: unauthenticated remote attackers can manipulate databases. No patch, product EOL. Isolate or discontinue use ASAP. Details: https://radar.offseq.com/threat/cve-2026-6887-cwe-89-improper-neutralization-of-sp-f0a62364 #OffSeq #SQLInjection #Vuln #InfoSec