Public disclosures highlighted multiple high-severity vulnerabilities across industrial control systems, open-source software, and consumer networking gear, with several issues enabling unauthenticated remote compromise. Johnson Controls disclosed CVE-2025-26385 (CVSS 10.0), a critical SQL injection affecting multiple building/ICS management products (including ADS/ADX, LCS8500, NAE8500, SCT, CCT) that can allow remote, unauthenticated attackers to execute arbitrary SQL to alter/delete/exfiltrate data; CISA guidance emphasized isolating control system networks from the internet, segmentation, and controlled remote access (e.g., VPNs). Additional unauthenticated remote issues include CVE-2026-25069 in SunFounder Pironman Dashboard (path traversal in log API endpoints enabling arbitrary file read/deletion) and CVE-2025-51958 in the DokuWiki runcommand plugin (unauthenticated command execution via lib/plugins/runcommand/postaction.php).
Other disclosures include developer-tooling and application-layer injection flaws and multiple router memory-corruption bugs with public exploit references. Orval fixed CVE-2026-25141, a code-injection issue where incomplete escaping can be bypassed using JSFuck-style payloads, and Cybersecurity AI (CAI) addressed CVE-2026-25130, where subprocess.Popen(..., shell=True) enables argument/command injection leading to RCE (notably via the find_file() tool). Data-layer issues include CVE-2025-69662 in geopandas (to_postgis() SQL injection) and CVE-2026-24854 in ChurchCRM (authenticated SQL injection via PerID in /PaddleNumEditor.php, patched in 6.7.2), while CVE-2025-36384 affects IBM Db2 for Windows (local privilege escalation via unquoted search path). SOHO router flaws CVE-2026-1686 (Totolink A3600R) and CVE-2026-1637 (Tenda AC21) describe remotely reachable buffer/stack overflows with publicly available exploit material, increasing the likelihood of opportunistic exploitation where exposed management interfaces exist.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-01, reporting said CISA had issued a critical advisory for CVE-2025-26385, a CVSS 10.0 SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. CISA recommended network isolation, firewalling, and use of patched VPNs for any remote access.
On 2026-02-01, disclosure@vulncheck.com received CVE-2026-25069 for a path traversal flaw in SunFounder Pironman Dashboard 1.3.13 and earlier. The issue allows unauthenticated remote attackers to read or delete arbitrary files through log file API endpoints.
By 2026-01-30, CVE-2026-1686 documented a remotely exploitable buffer overflow in the Totolink A3600R router's setAppEasyWizardConfig function in app.so. The disclosure referenced a public exploit and proof of concept, increasing the likelihood of real-world abuse.
A fix for CVE-2026-25130 was identified in commit e22a1220f764e2d7cf9da6d6144926f53ca01cde, addressing argument-injection flaws in Cybersecurity AI up to version 0.5.10. The vulnerabilities allowed arbitrary command execution, including through the pre-approved find_file() agent tool.
Orval addressed CVE-2026-25141, a code injection vulnerability caused by incomplete prior escaping logic, in versions 7.21.0 and 8.2.0. The issue allowed arbitrary JavaScript execution via crafted x-enum-descriptions using a JSFuck-style technique.
On 2026-01-30, CVE-2025-36384 was updated with CVSS v3.1 scoring, CWE-428 mapping, and an IBM PSIRT reference for a local privilege escalation issue in IBM Db2 for Windows 12.1.0 through 12.1.3. The flaw stems from an unquoted search path element and requires filesystem access.
On 2026-01-30, CVE-2025-51958 was documented and updated for an unauthenticated remote command execution flaw in the aelsantex runcommand plugin for DokuWiki. The update added references, a CVSS v3.1 vector, and CWE-78 classification.
On 2026-01-30, the CVE-2025-11175 entry was updated with a description, CVSS v4.0 vector, CWE-917 classification, and references for an expression language injection issue in MediaWiki DiscussionTools. The flaw can lead to Regular Expression Exponential Blowup in affected 1.43 and 1.44 versions.
On 2026-01-30, the CVE-2025-69662 record was updated to add a description, CVSS v3.1 vector, CWE classification, and references for an SQL injection issue in geopandas versions prior to 1.1.2. The flaw affects the to_postgis() function when writing GeoDataFrames to PostgreSQL.
ChurchCRM released version 6.7.2 to address CVE-2026-24854, a SQL injection flaw in /PaddleNumEditor.php that could be exploited by any authenticated user, even with no assigned permissions. The advisory references the fixing commit and GitHub Security Advisory.
On 2026-01-29, the CVE record for CVE-2026-1637 was received, documenting a remotely exploitable stack-based buffer overflow in the Tenda AC21 router's fromAdvSetMacMtuWan function. The record noted that a public exploit was available.
As of 2026-01-27, CISA said it was not aware of public exploitation of CVE-2025-26385, a critical SQL injection vulnerability affecting multiple Johnson Controls ICS products. The agency nevertheless highlighted the risk because the products are widely used in critical infrastructure environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.