Vulnerability Advisories

This page offers a comprehensive view of vulnerabilities identified by Nozomi Networks in critical OT, ICS, and IoT environments, showcasing the deep expertise and dedication of our world-class Security Research team.

Each advisory represents our ongoing effort to enhance the protection of industrial systems, identifying emerging threats before they can be exploited. Immediate protection is available through our Threat Intelligence (TI) subscription, supporting a proactive, forward-thinking defense strategy. For more on our responsible approach, refer to the Responsible Disclosure Policy.

Vulnerability Advisories

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Date Published
CVE ID
Vendor
Product
Type
Risk
Details
July 15, 2026
CVE-2026-56136
Tuxera
ntfs-3g
Out-of-bounds Read
Medium
July 15, 2026
CVE-2026-56135
Tuxera
ntfs-3g
Heap-based Buffer Overflow
High
July 15, 2026
CVE-2026-46572
Tuxera
ntfs-3g
Heap-based Buffer Overflow
High
July 15, 2026
CVE-2026-46571
Tuxera
ntfs-3g
Out-of-bounds Read
Medium
July 15, 2026
CVE-2026-46570
Tuxera
ntfs-3g
Heap-based Buffer Overflow
High
July 15, 2026
CVE-2026-46569
Tuxera
ntfs-3g
Heap-based Buffer Overflow
High
July 15, 2026
CVE-2026-42618
Tuxera
ntfs-3g
Off-by-one Error
High
July 15, 2026
CVE-2026-42617
Tuxera
ntfs-3g
Heap-based Buffer Overflow
High
July 15, 2026
CVE-2026-42616
Tuxera
ntfs-3g
Heap-based Buffer Overflow
High
July 20, 2026
CVE-2026-61378
Automationdirect
ADCUP Usb Driver
Divide By Zero
Medium
July 20, 2026
CVE-2026-60073
Automationdirect
ADCUP Usb Driver
Out-of-bounds Read
Medium
July 20, 2026
CVE-2026-57896
Automationdirect
ADCUP Usb Driver
Out-of-bounds Read
Medium
July 20, 2026
CVE-2026-60140
Automationdirect
ADCUP Usb Driver
Out-of-bounds Read
Medium
July 20, 2026
CVE-2026-61389
Automationdirect
ADCUP Usb Driver
Out-of-bounds Write
High
July 20, 2026
CVE-2026-60063
Automationdirect
ADCUP Usb Driver
Out-of-bounds Write
High
July 6, 2026
CVE-2026-13199
Raspberry Pi
Raspberry Pi 5
Insufficient Entropy
Medium
June 26, 2026
CVE-2026-57473
Reolink
Home Hub
Use of Weak Credentials
Medium
May 27, 2026
CVE-2025-41670
Phoenix Contact
PLCnext family
Uncontrolled Search Path Element
High
May 27, 2026
CVE-2025-41669
Phoenix Contact
PLCnext family
Improper Verification of Cryptographic Signature
High
May 29, 2026
CVE-2025-41281
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
May 29, 2026
CVE-2025-41280
Waterfall
WF-500
Relative Path Traversal
High
May 29, 2026
CVE-2025-41279
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
May 29, 2026
CVE-2025-41278
Waterfall
WF-500
Out-of-bounds Read
High
May 29, 2026
CVE-2025-41277
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41276
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41275
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41274
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41273
Waterfall
WF-500
Authentication Bypass Using an Alternate Path or Channel
Critical
May 29, 2026
CVE-2025-41272
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41271
Waterfall
WF-500
Relative Path Traversal
High
May 29, 2026
CVE-2025-41270
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41269
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41268
Waterfall
WF-500
Relative Path Traversal
High
May 29, 2026
CVE-2025-41267
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
May 29, 2026
CVE-2025-41266
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
May 29, 2026
CVE-2025-41265
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
March 24, 2026
CVE-2025-41660
CODESYS
Codesys Control
Incorrect Resource Transfer Between Spheres
High
March 19, 2026
CVE-2026-22323
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Cross-Site Request Forgery (CSRF)
High
March 19, 2026
CVE-2026-22322
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
High
March 19, 2026
CVE-2026-22318
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Stack-based Buffer Overflow
Medium
March 19, 2026
CVE-2026-22320
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Stack-based Buffer Overflow
Medium
March 19, 2026
CVE-2026-22317
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Improper Neutralization of Special Elements used in a Command ('Command Injection')
High
March 19, 2026
CVE-2026-22319
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Stack-based Buffer Overflow
Medium
March 19, 2026
CVE-2026-22316
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Stack-based Buffer Overflow
Medium
March 19, 2026
CVE-2026-22321
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Stack-based Buffer Overflow
Medium
March 10, 2026
CVE-2026-2273
Schneider Electric
EcoStruxure™ Automation Expert
Improper Control of Generation of Code ('Code Injection')
High
March 11, 2026
CVE-2026-22614
Eaton
EasySoft
Insufficiently Protected Credentials
Medium
March 9, 2026
CVE-2026-3588
Ikea
Dirigera
Server Side Request Forgery
High
February 23, 2026
CVE-2026-26098
Owl
opds
Uncontrolled Search Path Element
High
February 23, 2026
CVE-2026-26101
Owl
opds
Incorrect Permission Assignment for Critical Resource
High
February 23, 2026
CVE-2026-26099
Owl
opds
Uncontrolled Search Path Element
High
February 23, 2026
CVE-2026-26100
Owl
opds
Incorrect Permission Assignment for Critical Resource
Medium
February 23, 2026
CVE-2026-26102
Owl
opds
Incorrect Permission Assignment for Critical Resource
High
February 23, 2026
CVE-2026-26096
Owl
opds
Incorrect Permission Assignment for Critical Resource
High
February 23, 2026
CVE-2026-26094
Owl
opds
Use of Hard-coded Cryptographic Key
High
February 23, 2026
CVE-2026-26095
Owl
opds
Incorrect Permission Assignment for Critical Resource
High
February 23, 2026
CVE-2026-26093
Owl
opds
Improper Neutralization of Special Elements used in a Command ('Command Injection')
High
February 23, 2026
CVE-2026-2333
Owl
opds
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Critical
February 23, 2026
CVE-2026-26097
Owl
opds
Uncontrolled Search Path Element
High
January 30, 2026
CVE-2025-52600
Hanwha Vision
QNV-C8012
Client-Side Enforcement of Server-Side Security
Medium
January 30, 2026
CVE-2025-52599
Hanwha Vision
QNV-C8012
Incorrect Permission Assignment for Critical Resource
Medium
January 30, 2026
CVE-2025-8075
Hanwha Vision
QNV-C8012
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Medium
January 30, 2026
CVE-2025-52601
Hanwha Vision
Wisenet Device Manager
Use of Hard-coded Password
Medium
January 30, 2026
CVE-2025-52598
Hanwha Vision
QNV-C8012
Improper Certificate Validation
Medium
January 27, 2026
CVE-2025-41728
Beckhoff
TwinCAT Device Manager
Out-of-bounds Read
Medium
January 27, 2026
CVE-2025-41726
Beckhoff
TwinCAT Device Manager
Integer Overflow
High
January 27, 2026
CVE-2025-41727
Beckhoff
TwinCAT Device Manager
Unprotected Alternate Channel
High
November 28, 2025
CVE-2025-59890
Eaton
Galileo
Relative Path Traversal (ZipSlip)
High
November 18, 2025
CVE-2025-11243
Shelly
Pro 4PM
Allocation of Resources Without Limits or Throttling
High
November 18, 2025
CVE-2025-12056
Shelly
Pro 3EM
Out-of-bounds Read
High
October 10, 2025
CVE-2025-11678
warmcat
libwebsockets
Stack-based Buffer Overflow
High
October 10, 2025
CVE-2025-11680
warmcat
libwebsockets
Out-of-bounds Write
Medium
October 10, 2025
CVE-2025-11677
warmcat
libwebsockets
Use after free
Medium
October 10, 2025
CVE-2025-11679
warmcat
libwebsockets
Out-of-bounds Read
Medium
October 23, 2025
CVE-2025-62688
AutomationDirect
Productivity Suite
Incorrect Permission Assignment for Critical Resource
Medium
October 23, 2025
CVE-2025-60023
AutomationDirect
Productivity Suite
Relative Path Traversal
Medium
October 23, 2025
CVE-2025-58429
AutomationDirect
Productivity Suite
Relative Path Traversal
High
October 23, 2025
CVE-2025-59776
AutomationDirect
Productivity Suite
Relative Path Traversal
Medium
October 23, 2025
CVE-2025-61977
AutomationDirect
Productivity Suite
Weak Password Recovery Mechanism for Forgotten Password
High
October 23, 2025
CVE-2025-62498
AutomationDirect
Productivity Suite
Relative Path Traversal (ZipSlip)
High
October 23, 2025
CVE-2025-61934
AutomationDirect
Productivity Suite
Binding to an Unrestricted IP Address
Critical
October 23, 2025
CVE-2025-58078
AutomationDirect
Productivity Suite
Relative Path Traversal
High
October 23, 2025
CVE-2025-58456
AutomationDirect
Productivity Suite
Relative Path Traversal
High
September 25, 2025
CVE-2025-53947
Cognex
In-Sight Explorer Software
Incorrect Default Permissions
Medium
September 25, 2025
CVE-2025-54754
Cognex
In-Sight Explorer Software
Use of Hard-coded Password
High
September 25, 2025
CVE-2025-47698
Cognex
In-Sight Explorer Software
Cleartext Transmission of Sensitive Information
High
September 25, 2025
CVE-2025-52873
Cognex
In-Sight vision sensor series 2000, 7000, 8000 and 9000
Incorrect Permission Assignment for Critical Resource
High
September 25, 2025
CVE-2025-54810
Cognex
In-Sight vision sensor series 2000, 7000, 8000 and 9000
Authentication Bypass by Capture-replay
High
September 25, 2025
CVE-2025-54497
Cognex
In-Sight vision sensor series 2000, 7000, 8000 and 9000
Incorrect Permission Assignment for Critical Resource
High
September 25, 2025
CVE-2025-53969
Cognex
In-Sight vision sensor series 2000, 7000, 8000 and 9000
Cleartext Transmission of Sensitive Information
High
September 25, 2025
CVE-2025-54818
Cognex
In-Sight vision sensor series 2000, 7000, 8000 and 9000
Cleartext Transmission of Sensitive Information
High
September 25, 2025
CVE-2025-54860
Cognex
In-Sight vision sensor series 2000, 7000, 8000 and 9000
Improper Restriction of Excessive Authentication Attempts
Medium
September 24, 2025
CVE-2025-57882
AutomationDirect
CLICK PLUS
Improper Resource Shutdown or Release
Medium
September 24, 2025
CVE-2025-55069
AutomationDirect
CLICK PLUS
Predictable Seed in Pseudo-Random Number Generator
High
September 24, 2025
CVE-2025-55038
AutomationDirect
CLICK PLUS
Missing Authorization
Medium
September 24, 2025
CVE-2025-58069
AutomationDirect
CLICK PLUS
Use of Hard-coded Cryptographic Key
Medium
September 24, 2025
CVE-2025-58473
AutomationDirect
CLICK PLUS
Improper Resource Shutdown or Release
Medium
September 24, 2025
CVE-2025-54855
AutomationDirect
CLICK PLUS
Cleartext Storage of Sensitive Information
Medium
September 24, 2025
CVE-2025-59484
AutomationDirect
CLICK PLUS
Use of a Broken or Risky Cryptographic Algorithm
High
August 5, 2025
CVE-2025-41658
CODESYS
Codesys Control
Incorrect Default Permissions
Medium
CVE ID
CVE-2026-56136
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-56135
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-46572
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-46571
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-46570
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-46569
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-42618
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Off-by-one Error
Risk Score
High
CVE ID
CVE-2026-42617
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-42616
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-61378
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Divide By Zero
Risk Score
Medium
CVE ID
CVE-2026-60073
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-57896
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-60140
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-61389
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Write
Risk Score
High
CVE ID
CVE-2026-60063
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Write
Risk Score
High

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.