Virtual private network is a network security service that uses encrypted tunnels over public or shared networks to provide private, authenticated connectivity between users, sites, and cloud resources, supporting enterprise remote access, inter-site communication, and compliance with data-in-transit protection requirements.
AVEVA disclosed a vulnerability in its Application Server IDE, affecting versions up to 2023 R2 SP1 P02. The issue involves improper HTML tag neutralization, allowing potential XSS code exploitation. Recommended mitigations include updating to a later version and restricting network access.
Rockwell Automation's Studio 5000 Simulation Interface has multiple vulnerabilities, including path traversal and SSRF, impacting versions 2.02 and prior. Affected users are advised to upgrade to version 3.0.0 or later and implement security best practices to mitigate potential risks.
Rockwell Automation disclosed a vulnerability in FactoryTalk Policy Manager that could lead to denial of service. The affected versions are 6.51.00 and prior, with a CVSS v4 score of 8.7. Mitigations include updating to version 6.60.00 or later and following cybersecurity best practices.
Rockwell Automation has reported a vulnerability in its Verve Asset Manager affecting multiple versions, allowing unauthorized access via the API. Affected users are urged to update to versions 1.41.4 or 1.42. The vulnerability, identified as CVE-2025-11862, has a CVSS v4 score of 8.4.
Brightpick AI's warehouse automation platform is vulnerable to multiple security issues, allowing unauthorized access to critical functions and sensitive data. CISA recommends mitigations, but Brightpick has not engaged in collaborative response efforts. Users are encouraged to secure their systems against these vulnerabilities.
CISA, in collaboration with federal and international partners, has issued an updated Cybersecurity Advisory on Akira ransomware, detailing latest attack methods and prevention strategies.
Mitsubishi Electric has reported a vulnerability in its MELSEC iQ-F Series that may allow a Denial of Service condition when exploited. Affected models are detailed, and mitigation measures are recommended.
General Industrial Controls has reported vulnerabilities in Lynx+ Gateway, including weak password requirements and missing authentication, which could lead to unauthorized access. CISA recommends defensive measures to mitigate risks, as no public exploitation targeting these vulnerabilities has been documented.
AVEVA has reported a vulnerability in its Edge software that may allow attackers to reverse engineer passwords via weak cryptographic algorithms. Users are advised to upgrade to the latest version and implement specific security measures to mitigate risks.
Siemens has addressed vulnerabilities in Altair Grid Engine versions prior to V2026.0.0, which can allow attackers to escalate privileges. CISA advises updates, mitigations, and cybersecurity practices to minimize risks.