CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-94293 — An unauthenticated remote attacker can modify Asset Administration Shell submode...

·Source: NIST NVD

Updated:

Executive Summary

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.

Analysis

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints. CVSS Score: 9.8. Published: 2026-10-06T07:17:00.193.

Indicators of Compromise (1)

CVE (1)
CVE-2026-94293
Source Attribution

Originally published by NIST NVD on Oct 6, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-105778 — A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this...

A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2026-105778
NIST NVD
CRITICALVulnerability

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and

CVE-2026-21589
The Hacker News
MEDIUMVulnerability

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​

The Hacker News