A hidden backdoor function in the Contec CMS8000 patient monitor could give unauthorized access to patient data, warns the US Cybersecurity and Infrastructure Security Agency (CISA). The healthcare device is widely used across the US and EU. Exploiting the vulnerability could disrupt monitoring and lead to incorrect treatment. The backdoor lets the device execute unverified remote files, bypassing security protocols. Vendor updates have failed to remove the vulnerability. Secure networking experts Claroy suggest it was poor design, not malice.

Apache Parquet Java Vulnerability Let Attackers Execute Arbitrary Code
A critical vulnerability (CVE-2025-46762) in Apache Parquet Java allows arbitrary code execution via crafted Parquet files. Affecting all versions up to 1.15.1, it primarily concerns