Six publicly disclosed vulnerabilities across enterprise security, industrial control, and network-monitoring products. Summaries below are limited to details published by the vendors and coordinating authorities.

CVE-2026-20199

Cisco ThousandEyes Virtual Appliance

  • Type: Command injection / authenticated remote code execution (CWE-74)
  • Attack context: Remote, authenticated; valid administrative credentials required
  • Severity: CVSS v3.1 4.7
  • Summary: Insufficient validation in SSL certificate handling allows an administrator to upload a crafted certificate and execute commands as root on the appliance.
  • Vendor advisory: Cisco Security Advisory cisco-sa-tevacert-rce-RMJVEym5

CVE-2025-2297

BeyondTrust Privilege Management for Windows

  • Type: Privilege escalation through incorrect privilege assignment (CWE-268)
  • Attack context: Local, authenticated; standard user with the ability to edit their profile files
  • Severity: CVSS v4.0 7.2
  • Summary: Before version 25.4.270.0, a user can manipulate profile files to place illegitimate challenge-response codes in the local user registry and elevate to administrator.
  • Vendor advisory: BeyondTrust BT25-05

CVE-2024-0400

Hitachi Energy MACH SCM

  • Type: Code injection leading to remote code execution (CWE-94)
  • Attack context: Remote, authenticated client
  • Severity: CVSS v3.1 7.5
  • Summary: A malicious authenticated client can submit crafted code through SCM Server LINQ-query functionality, bypass validation, and execute arbitrary commands remotely on the server.
  • Vendor advisory: Hitachi Energy advisory 8DBD000189
  • Coordinating advisory: CISA ICSA-24-116-02

CVE-2024-2097

Hitachi Energy MACH SCM

  • Type: Eval injection / improper neutralization in dynamically evaluated code (CWE-95)
  • Attack context: Remote, authenticated List control client
  • Severity: CVSS v3.1 7.5
  • Summary: A malicious authenticated List control client can send a crafted LINQ query that SCM Server evaluates, allowing arbitrary code execution beyond the client’s intended authorization.
  • Vendor advisory: Hitachi Energy advisory 8DBD000189
  • Coordinating advisory: CISA ICSA-24-116-02

CVE-2023-33873

AVEVA Operations Control Logger used by multiple AVEVA products

  • Type: Execution with unnecessary privileges / privilege escalation (CWE-250)
  • Attack context: Local, OS-authenticated standard user
  • Severity: CVSS v3.1 7.8
  • Summary: A standard local user can exploit the logger’s excessive privileges to elevate to SYSTEM, resulting in complete compromise of the affected machine.
  • Vendor advisory: AVEVA Security Bulletin AVEVA-2023-003 (PDF)
  • Coordinating advisory: CISA ICSA-23-318-01

CVE-2023-34982

AVEVA Operations Control Logger used by multiple AVEVA products

  • Type: External control of file name or path (CWE-73)
  • Attack context: Local, OS-authenticated standard user
  • Severity: CVSS v3.1 7.1
  • Summary: A standard local user can cause files to be deleted with SYSTEM privileges on a machine running an affected product.
  • Vendor advisory: AVEVA Security Bulletin AVEVA-2023-003 (PDF)
  • Coordinating advisory: CISA ICSA-23-318-01