Skip to main content

Yacht Cybersecurity Alerts · Updated Hourly

Superyacht Cybersecurity Threat Intelligence

Live CVE alerts, CISA KEV vulnerabilities, NVD disclosures, and cyber news for yacht crews, ETOs, captains, managers, and onboard IT teams.

Updated 9 min ago

CISA KEV Watchlist for Yacht Cybersecurity

CISA Cybersecurity Risks for Yachts — Yacht-essentials

Active cyber threats that can reach the yacht through crew devices, remote access, onboard networks, and connected systems.

CVE-2025-68686 Actively exploited
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via anot…
Fortinet · FortiOS Added Jul 27, 2026 CISA due Aug 10, 2026
Read advisory at NVD →
CVE-2026-50522 Actively exploited
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Microsoft · SharePoint Added Jul 22, 2026 CISA due Jul 25, 2026
Read advisory at NVD →
CVE-2026-58644 Actively exploited
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Microsoft · SharePoint Added Jul 16, 2026 CISA due Jul 19, 2026
Read advisory at NVD →
CVE-2026-25089 Actively exploited
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Fortinet · FortiSandbox Added Jul 16, 2026 CISA due Jul 19, 2026
Read advisory at NVD →
CVE-2026-39808 Actively exploited
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Fortinet · FortiSandbox Added Jul 16, 2026 CISA due Jul 19, 2026
Read advisory at NVD →
CVE-2026-56164 Actively exploited
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Microsoft · SharePoint Server Added Jul 14, 2026 CISA due Jul 17, 2026
Read advisory at NVD →
CVE-2026-15409 Actively exploited
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
SonicWall · SMA1000 Appliances Added Jul 14, 2026 CISA due Jul 17, 2026
Read advisory at NVD →
CVE-2026-15410 Actively exploited
SonicWall SMA1000 Appliances Code Injection Vulnerability
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
SonicWall · SMA1000 Appliances Added Jul 14, 2026 CISA due Jul 17, 2026
Read advisory at NVD →
CVE-2008-4128 Actively exploited
Cisco IOS Cross-Site Request Forgery Vulnerability
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
Cisco · IOS Added Jul 13, 2026 CISA due Jul 16, 2026
Read advisory at NVD →
CVE-2026-45659 Actively exploited
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
Microsoft · SharePoint Server Added Jul 1, 2026 CISA due Jul 4, 2026
Read advisory at NVD →
CVE-2026-20230 Actively exploited
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.
Cisco · Unified Communications Manager Added Jun 25, 2026 CISA due Jun 28, 2026
Read advisory at NVD →
CVE-2026-34910 Actively exploited
Ubiquiti UniFi OS Improper Input Validation Vulnerability
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Ubiquiti · UniFi OS Added Jun 23, 2026 CISA due Jun 26, 2026
Read advisory at NVD →
See the full Yacht-essentials catalog (153 entries) →

Filtered to Yacht-essentials. Search, sort, and paginate the rest on the full catalog page.

Want crew who know what to do when one of these lands in their inbox? Start the free hour-long course →

Superyacht Cybersecurity Risks

New CVE Risks for Yacht IT

Recently disclosed CVEs ranked critical-first for yacht IT, AV, remote access, firewalls, routers, and onboard networks.

CVE CVSS Severity Published Description
CVE-2026-57331 9.9 CRITICAL Jun 29, 2026 Performer Arbitrary File Deletion in Paid Videochat Turnkey Site
CVE-2026-13763 9.8 CRITICAL Jun 29, 2026 Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2 ALB target groups. To remediate this is…
CVE-2026-13762 9.8 CRITICAL Jun 29, 2026 Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue was remediated server-side. No customer action is required.
CVE-2026-56782 9.8 CRITICAL Jun 29, 2026 Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default configuration. Remote attackers can exfiltrate the entire database including user records, items, and feedback data containin…
CVE-2026-56290 9.8 CRITICAL Jun 29, 2026 Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVE-2026-49048 9.8 CRITICAL Jun 28, 2026 The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.
CVE-2026-39868 9.1 CRITICAL Jun 29, 2026 This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
CVE-2026-37637 9.1 CRITICAL Jun 29, 2026 An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component
CVE-2026-11720 9.1 CRITICAL Jun 29, 2026 A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While it checks that the input does not alter the scheme, host, or user info, it relie…
CVE-2026-43705 8.8 HIGH Jun 29, 2026 A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
CVE-2026-58000 8.8 HIGH Jun 29, 2026 luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN protocol configuration access can inject arbitrary shell metacharacters into cl_meta…
CVE-2026-57999 8.8 HIGH Jun 29, 2026 luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-controlled loginserver and loginserver_authkey parameters are improperly quoted within a double-quoted shell command, allowing shell substitu…
CVE-2026-41052 8.8 HIGH Jun 29, 2026 Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
CVE-2026-13749 8.8 HIGH Jun 29, 2026 Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 allowed arbitrary code execution during application bundling or deployment. An attacker could exploit this by supplying crafted project content that is interpolated into generated Python code, causing Snowflake CLI to execute attacker-contr…
CVE-2026-13583 8.8 HIGH Jun 29, 2026 A vulnerability has been found in Edimax EW-7478APC 1.04. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. Such manipulation of the argument ShareName/SelectName leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The v…
CVE-2026-13582 8.8 HIGH Jun 29, 2026 A flaw has been found in Edimax EW-7478APC 1.04. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. This manipulation of the argument UserName/Password causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was…
CVE-2026-13580 8.8 HIGH Jun 29, 2026 A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was co…
CVE-2026-55607 8.8 HIGH Jun 29, 2026 Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite…
CVE-2026-40521 8.8 HIGH Jun 29, 2026 FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute arbitrary code by uploading files with traversal sequences in the unique_name parameter. Attackers can supply path traversal sequences ../../../shell.php to write files outside the intended attachments directo…
CVE-2026-12856 8.8 HIGH Jun 29, 2026 A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an attacker can execute arbitrary VS Code comma…
CVE-2026-13564 8.8 HIGH Jun 29, 2026 A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The vend…
CVE-2026-13563 8.8 HIGH Jun 29, 2026 A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be u…
CVE-2026-13562 8.8 HIGH Jun 29, 2026 A flaw has been found in Edimax EW-7478APC 1.04. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. This manipulation of the argument selSSID causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted…
CVE-2026-25707 8.8 HIGH Jun 29, 2026 A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
CVE-2026-13545 8.8 HIGH Jun 29, 2026 A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi of the component POST Parameter Handler. Such manipulation of the argument UID leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Phishing emails carry these payloads. Train crew to spot the trigger →

From the Cybersecurity Newsroom

What's making cyber headlines

Hand-picked feeds from Krebs on Security, The Hacker News, BleepingComputer, and SANS ISC.

BleepingComputer
vBulletin fixes critical pre-auth RCE flaw with public exploit
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]
Jul 28, 2026
Read at source →
The Hacker News
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dro…
Jul 28, 2026
Read at source →
The Hacker News
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed server-management…
Jul 28, 2026
Read at source →
BleepingComputer
Is Your SSO Protected Against Modern Credential Attacks?
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. [..…
Jul 28, 2026
Read at source →
The Hacker News
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved lat…
Jul 28, 2026
Read at source →
The Hacker News
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unaut…
Jul 28, 2026
Read at source →
BleepingComputer
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]
Jul 28, 2026
Read at source →
The Hacker News
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve…
Jul 28, 2026
Read at source →
BleepingComputer
Data breach at medical billing firm MCBS affects 1.26 million people
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]
Jul 28, 2026
Read at source →
SANS Internet Storm Center
AutoIT Payload Injector , (Tue, Jul 28th)
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it&#x27s easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you&#x27ll see below.&#xd;
Jul 28, 2026
Read at source →
SANS Internet Storm Center
ISC Stormcast For Tuesday, July 28th, 2026 https://isc.sans.edu/podcastdetail/10026, (Tue, Jul 28th)
Jul 28, 2026
Read at source →
BleepingComputer
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]
Jul 27, 2026
Read at source →

Headlines and snippets © their respective publishers; links go directly to the original sources.

IoT · The overlooked threat surface

IoT on yachts: what most owners miss

Yachts pack more network-connected gadgets than a small office — cameras, AV controllers, smart locks, sensors, infotainment. Most of it ships with weak defaults and never gets patched. Here are the three archetypes we keep seeing in incident reports.

01 Cameras · DVRs
The camera you forgot to patch
IP cameras (Hikvision, Dahua, Axis), smart doorbells, and baby monitors aboard frequently ship with hardcoded creds, open telnet, or unpatched RTSP stacks. One compromised camera = a foothold on the yacht LAN, often with privileged network access for "remote viewing."
Watch for: default passwords, firmware >2 yr old, port 23 open on the guest VLAN
Train crew on device hygiene →
02 AV · Control
Crestron, Lutron, Control4, Savant
AV/lighting/climate controllers expose web admin panels and REST APIs that historically ship with weak auth. They share the same LAN as crew laptops and bridge systems, so a compromise gets full lateral access. Patch cadence is usually "never" without a dedicated integrator.
Watch for: control panels reachable from the guest network, no MFA on admin UIs, vendor remote-access tunnels left enabled
Train crew on segmentation →
03 Guest gear
The "smart" bits guests bring aboard
Chromecasts, Sonos, AirPlay receivers, Bluetooth speakers, smart TVs. Every one is an unmanaged endpoint that broadcasts on the network and can bridge guest devices into the yacht's primary VLAN if segmentation is loose. They're also notorious for shipping with mDNS/UPnP scanning enabled.
Watch for: charter guests plugging anything into wired ports, "easier" flat networks, no MAC allowlist on the crew VLAN
Train crew on guest policy →

Why this matters at sea

Most of these attacks start with a person, not a firewall

Phishing, hostile marina Wi-Fi, guest data slip-ups — the techniques behind the headlines are the same ones that target crew inboxes every day.

Enroll your yacht

Ready to harden your crew's
cyber posture?

Contact us +1.754.600.8735