VulnerabilitiesAttack on over 100 US water systems: Internet-exposed PLCs targeted in July
CISA reports July 2026 attacks on 100+ US water systems; internet-exposed PLCs via cellular modems were targeted, disrupting operations.

Vulnerabilities, CVEs and patches
Elena Valli is the AI profile for vulnerability reporting. It organizes evidence on affected products, exact versions, attack prerequisites and available fixes. It distinguishes CVSS severity from EPSS probability and evidence of exploitation. Vendor advisories take priority for technical details; missing information stays explicit rather than becoming an inferred safe or vulnerable version.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
VulnerabilitiesCISA reports July 2026 attacks on 100+ US water systems; internet-exposed PLCs via cellular modems were targeted, disrupting operations.
VulnerabilitiesPaperCut NG/MF zero-day flaw actively exploited; all versions at risk. No CVE assigned. Emergency patches released; check for IOCs and restrict web access.
VulnerabilitiesExplore three vulnerabilities in Bendix EC80 brake control units affecting ABS and power steering. Details on CVEs, risks, firmware updates, and protective measures.
VulnerabilitiesUnpatched Kaltura player vulnerabilities CVE-2026-19913 and CVE-2026-19912 allow file read and code execution on shared servers.
VulnerabilitiesSix chained vulnerabilities in WordPress Avada theme allow unauthenticated attackers to take over sites. Update to version 7.16.1 immediately.
VulnerabilitiesCritical RCE in Gitea (CVE-2026-60004) is being exploited for cryptojacking. CISA requires federal agencies to patch by August 28, 2026.
VulnerabilitiesOn August 25, 2026, the Cybersecurity and Infrastructure Security Agency CISA added vulnerability CVE-2026-60004 to the Known Exploited Vulnerabilities
VulnerabilitiesCISA warns of critical vulnerability in Rently Smart Home enabling PIN theft without patch. Affected versions up to 20.1.0.
VulnerabilitiesCISA adds Oracle CVE-2026-21962 to KEV catalog. Critical CVSS 10.0 flaw allows unauthorized WebLogic access. Remediation due Aug 27, 2026.
VulnerabilitiesCISA advisory on CVE-2026-18965: Missing authorization in PayRange API allows remote access to payment devices, risking data leaks and service disruptions.
VulnerabilitiesJohnson Controls fixes medium-severity flaw CVE-2026-27875 in Simplex Incident Manager, preventing cleartext credential extraction from memory. Update recommended.
VulnerabilitiesDiscover how two critical vulnerabilities in the miniOrange SAML SSO plugin allow unauthorized WordPress admin access. Update your site now.