Перейти к содержимому
Noroxi

Вторник обновлений

май 2026 г.

Во второй вторник месяца Microsoft, Adobe, SAP, Siemens и Schneider Electric публикуют пакетно; Oracle — в третий вторник января, апреля, июля и октября. Здесь записи того дня из нашей базы, по баллу действия: сначала KEV и зрелые эксплойты.

Как считается: метка CNA + дата публикации (окно два дня, UTC). Полного соответствия бюллетеню производителя не утверждается; внеплановые обновления выходят в другие дни.

записей: 197 · KEV: 0

Затрагивают ваш стек

Записи этого месяца, совпадающие с продуктами и версиями вашего стека.

Войдите, чтобы увидеть совпадения со стеком; записи и уведомления бесплатны. →

Microsoft · 12 мая

125 · KEV: 0 · критических: 9

+113 ещёВсе записи производителя

Adobe · 12 мая

51 · KEV: 0 · критических: 2

+39 ещёВсе записи производителя

SAP · 12 мая

0 · KEV: 0 · критических: 0

В этом окне записей нет.

Siemens · 12 мая

18 · KEV: 0 · критических: 3
  • CVE-2026-25786
    37Наблюдать

    Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    siemens · simatic drive controller cpu 1504d tf12 мая 2026 г.

  • CVE-2026-25787
    37Наблюдать

    Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    siemens · simatic drive controller cpu 1504d tf12 мая 2026 г.

  • CVE-2026-41551
    37Наблюдать

    A vulnerability has been identified in ROS# (All versions < V2.2.2).

    КритическаяCVSS 9,3Proof of conceptEPSS 1 %

    siemens · ros#12 мая 2026 г.

  • CVE-2025-40949
    35Наблюдать

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGE

    ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %

    siemens · ruggedcom rox mx5000 firmware12 мая 2026 г.

  • CVE-2026-22924
    35Наблюдать

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0).

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    siemens · simatic cn 4100 firmware12 мая 2026 г.

  • CVE-2025-40833
    34Наблюдать

    The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests.

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    siemens · ie/pb link ha12 мая 2026 г.

  • CVE-2026-22925
    34Наблюдать

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0).

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    siemens · simatic cn 4100 firmware12 мая 2026 г.

  • CVE-2026-33862
    34Наблюдать

    A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcente

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    siemens · teamcenter12 мая 2026 г.

  • CVE-2026-33893
    34Наблюдать

    A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcente

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    siemens · teamcenter12 мая 2026 г.

  • CVE-2025-40947
    30Наблюдать

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGE

    ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %

    siemens · ruggedcom rox mx5000 firmware12 мая 2026 г.

  • CVE-2026-44411
    29Наблюдать

    A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5).

    ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %

    siemens · solid edge se202612 мая 2026 г.

  • CVE-2026-44412
    29Наблюдать

    A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5).

    ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %

    siemens · solid edge se202612 мая 2026 г.

+6 ещёВсе записи производителя

Schneider Electric · 12 мая

3 · KEV: 0 · критических: 0
  • CVE-2026-4827
    34Наблюдать

    Insufficient Entropy vulnerability on Multiple Products

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    schneider electric · easergy micom c26412 мая 2026 г.

  • CVE-2026-6866
    32Наблюдать

    Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel Server

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    schneider-electric · ecostruxure panel server pas400 firmware12 мая 2026 г.

  • CVE-2026-6865
    28Наблюдать

    Improper Limitation of a Pathname to a Restricted Directory Vulnerability on Multiple Products

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    schneider electric · easylogic t150 (formerly saitel dr) remote terminal unit & controller12 мая 2026 г.

Все записи производителя