Security Vulnerabilities & CVE Database

Browse the latest CVE vulnerability disclosures, CISA KEV alerts, and OSV advisories. Real-time security vulnerability database curated by 10alert.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

Siemens gWAP Vulnerability Exposes Systems to Remote Code Execution

A critical remote code execution (RCE) vulnerability (CVE-2026-40175) in Siemens gWAP versions below 3.1.1 results from a prototype pollution flaw in the Axios HTTP client library. Attackers can exploit this to execute arbitrary code on industrial systems, exposing critical manufacturing and infrastructure to severe compromise. Siemens has released version 3.1.1 to patch the flaw, and immediate updates are required to mitigate active exploitation risks.

CVEs: CVE-2026-40175

#siemens #rce #cve-2026-40175 #prototype-pollution #industrial-security

Read full article →

Siemens SIMATIC CN 4100 Hit by 150+ Critical Linux Kernel Vulnerabilities

Siemens SIMATIC CN 4100, an industrial Linux-based control system, is affected by over 150 critical Linux kernel vulnerabilities. These flaws expose the system to remote code execution, denial-of-service, privilege escalation, and data breaches, posing severe risks to industrial operations. Immediate patching to firmware version V5.0+ is required.

CVEs: CVE-2024-47704, CVE-2024-57924, CVE-2024-58240, CVE-2025-6021, CVE-2025-6052

#siemens #linux-kernel #cve #industrial-security #patch-management

Read full article →

Siemens Solid Edge Vulnerabilities Allow Arbitrary Code Execution

Two high-severity buffer-overflow vulnerabilities (CVE-2026-44411 and CVE-2026-44412) in Siemens Solid Edge SE2026 allow attackers to execute arbitrary code or crash the application by exploiting maliciously crafted PAR files. All versions prior to Update 5 (226.0.5) are affected, posing critical risks to manufacturing and engineering sectors relying on this CAD software. Users must update immediately to mitigate exploitation risks.

CVEs: CVE-2026-44411, CVE-2026-44412

#siemens #solid-edge #cve-2026-44411 #cve-2026-44412 #buffer-overflow

Read full article →

Critical Vulnerability in Siemens Opcenter RDnL: Authentication Flaw Exposes Systems

Siemens Opcenter RDnL contains a critical authentication flaw in ActiveMQ Artemis (CVE-2026-27446) that enables unauthenticated attackers to inject malicious messages or disrupt operations. All versions of Opcenter RDnL are affected, allowing adversaries on adjacent networks to establish rogue connections and manipulate industrial systems. Siemens urges immediate updates to mitigate risks of data exfiltration or sabotage.

CVEs: CVE-2026-27446

#siemens #activemq-artemis #cve-2026-27446 #critical-vulnerability #industrial-security

Read full article →