Antivirus software is security software that detects, prevents and removes malware on endpoints and other systems, using signature-based and behavioral techniques, and serves as a core control in enterprise endpoint protection, compliance programs and incident detection workflows.
ABB's FLXeon Controllers are identified with multiple vulnerabilities, including hard-coded credentials and improper input validation, allowing potential remote exploitation. Users are advised to implement mitigation strategies and update firmware to enhance security.
AVEVA disclosed a vulnerability in its Application Server IDE, affecting versions up to 2023 R2 SP1 P02. The issue involves improper HTML tag neutralization, allowing potential XSS code exploitation. Recommended mitigations include updating to a later version and restricting network access.
Rockwell Automation's Studio 5000 Simulation Interface has multiple vulnerabilities, including path traversal and SSRF, impacting versions 2.02 and prior. Affected users are advised to upgrade to version 3.0.0 or later and implement security best practices to mitigate potential risks.
Rockwell Automation has reported a vulnerability in its Verve Asset Manager affecting multiple versions, allowing unauthorized access via the API. Affected users are urged to update to versions 1.41.4 or 1.42. The vulnerability, identified as CVE-2025-11862, has a CVSS v4 score of 8.4.
Brightpick AI's warehouse automation platform is vulnerable to multiple security issues, allowing unauthorized access to critical functions and sensitive data. CISA recommends mitigations, but Brightpick has not engaged in collaborative response efforts. Users are encouraged to secure their systems against these vulnerabilities.
Mitsubishi Electric has reported a vulnerability in its MELSEC iQ-F Series that may allow a Denial of Service condition when exploited. Affected models are detailed, and mitigation measures are recommended.
General Industrial Controls has reported vulnerabilities in Lynx+ Gateway, including weak password requirements and missing authentication, which could lead to unauthorized access. CISA recommends defensive measures to mitigate risks, as no public exploitation targeting these vulnerabilities has been documented.
AVEVA has reported a vulnerability in its Edge software that may allow attackers to reverse engineer passwords via weak cryptographic algorithms. Users are advised to upgrade to the latest version and implement specific security measures to mitigate risks.
Siemens has addressed vulnerabilities in Altair Grid Engine versions prior to V2026.0.0, which can allow attackers to escalate privileges. CISA advises updates, mitigations, and cybersecurity practices to minimize risks.