Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Spain secures €200 million in EU funding to expand EV value chain

How Indaver became a pioneer in PFAS destruction

China-linked hackers use TernDoor, PeerTime, and BruteEntry in communications attacks in South America

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Hikvision and Rockwell Automation CVSS 9.8 defects added to CISA KEV catalog
Identity

Hikvision and Rockwell Automation CVSS 9.8 defects added to CISA KEV catalog

userBy userMarch 6, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMarch 6, 2026Vulnerability/Network Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws affecting Hikvision and Rockwell Automation products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The critical severity vulnerabilities are:

CVE-2017-7921 (CVSS Score: 9.8) – Improper authentication vulnerability affecting multiple Hikvision products could allow a malicious user to escalate privileges on the system and access sensitive information. CVE-2021-22681 (CVSS Score: 9.8) – An insufficiently protected credentials vulnerability affecting multiple Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix controllers could allow an unprivileged user with network access to the controller to bypass validation mechanisms to authenticate or modify configuration or application code.

The addition of CVE-2017-7921 to the KEV catalog comes more than four months after the SANS Internet Storm Center revealed that it had detected an exploitation attempt against Hikvision cameras susceptible to this flaw. However, there appear to be no public reports describing attacks related to CVE-2021-22681.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are encouraged to update to the latest supported software version by March 26, 2026 as part of Binding Operational Directive (BOD) 22-01.

“These types of vulnerabilities are frequent attack vectors for malicious cyber attackers and pose significant risks to federal enterprises,” CISA said.

“While BOD 22-01 applies only to FCEB institutions, CISA urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of vulnerabilities in the KEV catalog as part of their vulnerability management practices.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleAntropic challenges Department of Defense supply chain label in court
Next Article Microsoft reveals ClickFix campaign to deploy Lumma Stealer using Windows Terminal
user
  • Website

Related Posts

China-linked hackers use TernDoor, PeerTime, and BruteEntry in communications attacks in South America

March 6, 2026

Microsoft reveals ClickFix campaign to deploy Lumma Stealer using Windows Terminal

March 6, 2026

Post-Quantum Cryptography Webinar for Security Leaders

March 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Spain secures €200 million in EU funding to expand EV value chain

How Indaver became a pioneer in PFAS destruction

China-linked hackers use TernDoor, PeerTime, and BruteEntry in communications attacks in South America

High-performance large language models for Europe

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.