Vulnerabilities

Summary — last 7 days

New vulnerabilities2,699▼ 343 vs. last week
Critical / high1,270▼ 197 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)208▼ 123 vs. last week
–

7 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedHigh (7)0.33%—Schneider-electric Ecostruxure Foxboro DCS Control Software3/10/20266/24/2026
CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file.
ModifiedHigh (7.8)0.24%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services7/11/20246/17/2026
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
ModifiedMedium (5.5)0.15%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services7/11/20246/17/2026
CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
ModifiedHigh (7.1)0.15%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services7/11/20246/17/2026
CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
ModifiedHigh (7.8)0.16%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services6/14/20236/17/2026
A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an unpredictable index to an IOCTL call in the Foxboro.sys driver.
ModifiedHigh (7.8)0.19%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services6/14/20236/17/2026
A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
ModifiedHigh (8.7)0.32%—Schneider-electric Foxboro DCSSchneider-electric Foxboro EVOSchneider-electric FoxviewSchneider-electric IA Series12/24/20186/17/2026
A Credential Management vulnerability exists in FoxView HMI SCADA (All Foxboro DCS, Foxboro Evo, and IA Series versions prior to Foxboro DCS Control Core Services 9.4 (CCS 9.4) and FoxView 10.5.) which could cause unauthorized disclosure, modification, or disruption in service when the password is modified without…
Orbitaley — Vulnerabilities