Live
CISA Adds Actively Exploited Trend Micro Apex One Zero-Day to KEV, Mandates Rapid Patching·MSFT +2.1%Cisco Rushes Patch for Critical 10.0 Bug Exposing Firewall Managers to Pre-Auth Shell Attacks·NVDA +0.2%Google Chrome 139.0.7258.127 Plugs Aura Use-After-Free (CVE-2025-8882) and Other High-Severity Bugs·GOOGL +1.7%Chrome 139 Fixes High-Severity libaom AV1 Heap Overflow; Edge Patch to Follow·AMZN +1.1%Chrome's File Picker Cross-Origin Leak Prompts Emergency Patch for Windows Browsers·MSFT +2.1%Siemens Admits No Fix Planned for Critical PLCSIM Vulnerability as TIA Portal Flaw Scores 8.5 CVSS·NVDA +0.2%CISA Flags 32 Critical Flaws in Siemens and Rockwell Gear—Some Require Physical Resets·GOOGL +1.7%Siemens CROSSBOW SAC Emergency Patch: Critical SQLite Flaws Enable Remote Code Execution·AMZN +1.1%CISA Adds Actively Exploited Trend Micro Apex One Zero-Day to KEV, Mandates Rapid Patching·MSFT +2.1%Cisco Rushes Patch for Critical 10.0 Bug Exposing Firewall Managers to Pre-Auth Shell Attacks·NVDA +0.2%Google Chrome 139.0.7258.127 Plugs Aura Use-After-Free (CVE-2025-8882) and Other High-Severity Bugs·GOOGL +1.7%Chrome 139 Fixes High-Severity libaom AV1 Heap Overflow; Edge Patch to Follow·AMZN +1.1%Chrome's File Picker Cross-Origin Leak Prompts Emergency Patch for Windows Browsers·MSFT +2.1%Siemens Admits No Fix Planned for Critical PLCSIM Vulnerability as TIA Portal Flaw Scores 8.5 CVSS·NVDA +0.2%CISA Flags 32 Critical Flaws in Siemens and Rockwell Gear—Some Require Physical Resets·GOOGL +1.7%Siemens CROSSBOW SAC Emergency Patch: Critical SQLite Flaws Enable Remote Code Execution·AMZN +1.1%

Vulnerability

The latest Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 9:58 AM
Latest Most Read Breaking
Sort
Bod 22-01 · Cisa

CISA Adds Actively Exploited Trend Micro Apex One Zero-Day to KEV, Mandates Rapid Patching

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-54948, a critical command injection vulnerability in Trend Micro’s Apex One on-premises management console, to...

Advertisement
Browser Security · Chrome

Chrome's File Picker Cross-Origin Leak Prompts Emergency Patch for Windows Browsers

A critical logic flaw in Chromium's File Picker—one of the browser's most sensitive UI components—can be weaponized to leak data across origins, forcing Google and Microsoft to ship urgent...

SE Security Desk·48w ago
siemens_admits_no_fix.jpg
Application Whitelisting · Cisa

Siemens Admits No Fix Planned for Critical PLCSIM Vulnerability as TIA Portal Flaw Scores 8.5 CVSS

Siemens has disclosed a high-severity deserialization vulnerability in its TIA Portal engineering platform that carries a CVSS v4 score of 8.5, and in a troubling admission, says no fix is planned...

SE Security Desk·48w ago
cisa_flags_32_critical.jpg
Armorblock · Asset Inventory

CISA Flags 32 Critical Flaws in Siemens and Rockwell Gear—Some Require Physical Resets

Federal cybersecurity officials on August 14 published thirty-two advisories covering industrial control systems from Siemens, Rockwell Automation, and other vendors, warning that many of the...

SE Security Desk·48w ago
siemens_crossbow_sac_emergency.jpg
Cisa · Crossbow

Siemens CROSSBOW SAC Emergency Patch: Critical SQLite Flaws Enable Remote Code Execution

Siemens has released emergency patches for its RUGGEDCOM CROSSBOW Station Access Controller (SAC) after security researchers uncovered multiple critical vulnerabilities in the SQLite database engine...

SE Security Desk·48w ago
siemens_rtls_backup_script.jpg
Backup Scripts · Cve-2025

Siemens RTLS Backup Script Vulnerability Allows Full SYSTEM Takeover

A single flawed backup script in Siemens' industrial location tracking software can hand an attacker full SYSTEM-level control of the underlying Windows server. That is the sobering reality of...

SE Security Desk·48w ago
Cve-2025-40584 · Cwe-611

CVE-2025-40584: Siemens SIMOTION and SINAMICS Tools Vulnerable to XXE File Disclosure, Some Left Unpatched

Siemens has acknowledged a critical XML External Entity (XXE) vulnerability—tracked as CVE-2025-40584—affecting multiple versions of its SIMOTION SCOUT, SIMOTION SCOUT TIA, and SINAMICS STARTER...

SE Security Desk·48w ago
Cisa · Cve-2025-7532

Rockwell Automation Patches FactoryTalk Action Manager Vulnerability That Broadcasts API Tokens

Rockwell Automation has confirmed a high-severity information disclosure vulnerability in its FactoryTalk Action Manager software that broadcasts reusable API tokens over local WebSocket channels,...

SE Security Desk·48w ago
Cisa · Cve

Siemens SINEC OS Advisory Exposes Over 100 Third-Party Kernel Flaws, Shifts Patch Burden to ProductCERT

Siemens has released a sprawling security advisory covering third-party components inside its SINEC operating system, cataloguing more than a hundred Linux kernel and userland vulnerabilities that...

SE Security Desk·48w ago