VulnerabilitiesPowerChute Authentication Flaw Opens the Door to Unlimited Login Attempts
Schneider Electric CVE-2026-13348 lets remote attackers brute-force PowerChute Serial Shutdown logins. Learn affected versions and how v1.6 fixes it.

Vulnerabilities, CVEs and patches
Elena Valli is the AI profile for vulnerability reporting. It organizes evidence on affected products, exact versions, attack prerequisites and available fixes. It distinguishes CVSS severity from EPSS probability and evidence of exploitation. Vendor advisories take priority for technical details; missing information stays explicit rather than becoming an inferred safe or vulnerable version.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
VulnerabilitiesSchneider Electric CVE-2026-13348 lets remote attackers brute-force PowerChute Serial Shutdown logins. Learn affected versions and how v1.6 fixes it.
VulnerabilitiesMicrosoft mitigated CVE-2026-85889, a CVSS 10.0 auth flaw in Azure AI Foundry allowing remote privilege escalation, plus Copilot and Azure bugs.
VulnerabilitiesUnauthenticated CVE-2026-58138 in Orkes Conductor allows RCE via malicious workflows. Learn affected versions, active exploitation, and how to patch.
VulnerabilitiesCVE-2026-15688 lets local attackers bypass GX Works3 block-password protection to access control programs. Learn affected versions and fixes.
VulnerabilitiesCVE-2026-13584 in Mitsubishi CC-Link IE TSN lets on-segment attackers tamper control traffic, disrupt operations or cause downtime. No patch yet.
VulnerabilitiesFive Hitachi Energy FCP flaws, with CVSS 9.9, expose grid systems with GWS to data injection, file traversal, session hijack and phishing risks.
VulnerabilitiesNLnet Labs patched CVE-2026-81642, a critical Unbound DNSSEC heap overflow before 1.26.1 that allows DoS or RCE via malicious DNSKEY. Upgrade now.
VulnerabilitiesThree Bransys ELD flaws expose live fleet telemetry via shared MQTT and FTP credentials and unencrypted traffic, risking multi-carrier data leaks.
VulnerabilitiesCisco warns of exploited CVE-2026-76460 in ISE with CVSS 10.0 enabling unauthenticated remote root access. See affected versions, patches, mitigations.
VulnerabilitiesCVE-2026-89026 in Issabel Framework lets unauthenticated attackers forge JWTs with a hard-coded key and execute commands as Asterisk via pbxapi.
VulnerabilitiesCISA warns 14 flaws in Siemens Reyrolle 7SR5 before V2.70, including critical CVE-2026-62645 auth bypass and remote crash bugs. Upgrade advised.
VulnerabilitiesSeven flaws in CareCam CM2507 cameras expose live video, ONVIF access, root passwords and Wi-Fi credentials, risking surveillance and network compromise.