Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryindustrial-control-system-vulnerabilityendpoint-software-vulnerabilityopen-source-dependency-vulnerability

Early March 2026 Vendor Security Advisories and Patch Releases Across Enterprise, Mobile, and ICS Products

Updated 3mo agoFirst seen Mar 3, 202610 sources

Multiple vendors issued security advisories and patch releases in late February and early March 2026, prompting coordinated update guidance from national and regional CERTs. The Canadian Centre for Cyber Security highlighted updates for Django (fixed in 4.2.29, 5.2.12, 6.0.3), Samsung mobile devices (March 2026 security update), Qualcomm (March 2026 monthly bulletin), Veeam Kasten for Kubernetes / Kasten K10, VMware Tanzu components (including Greenplum and RabbitMQ on Kubernetes), and Red Hat advisories including Linux kernel updates across multiple RHEL-related platforms.

Industrial and infrastructure-facing products were also covered via CISA ICS advisories spanning a broad set of vendors and solutions (including EV charging ecosystems, building management, cameras, and DCS/SCADA platforms such as Schneider Electric EcoStruxure Building Operation Workstation and Yokogawa CENTUM VP), with guidance to apply mitigations and updates where available. Additional enterprise patch guidance included Dell advisories affecting PowerStore T and PowerEdge server lines (including AMD-based models and NVIDIA networking/DOCA-related components), and IBM advisories across a wide portfolio (including App Connect Enterprise, CICS TX, License Metric Tool, Maximo, Sterling Secure Proxy, Terracotta, QRadar, and others). HKCERT separately summarized Samsung vulnerabilities impacting Android devices and Exynos chipsets, listing multiple CVEs (e.g., CVE-2024-31328 and numerous 2025-series CVEs) with potential impacts including RCE, EoP, information disclosure, and DoS.

Share:
Early March 2026 Vendor Security Advisories and Patch Releases Across Enterprise, Mobile, and ICS Products
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Mar 3, 20264mo ago

Django publishes security advisory for supported release lines

On 2026-03-03, Django published a security advisory covering vulnerabilities in supported release lines, including Django 4.2 before 4.2.29, Django 5.2 before 5.2.12, and Django 6.0 before 6.0.3. The advisory instructed users to review the notice and update to fixed versions.

Samsung publishes mobile device security update

On 2026-03-03, Samsung released a security update for mobile devices addressing multiple vulnerabilities affecting versions prior to SMR-MAR-2026. Users and administrators were directed to Samsung's security update information for remediation details.

Mar 2, 20264mo ago

Qualcomm publishes March 2026 security bulletin

On 2026-03-02, Qualcomm published its March 2026 security bulletin addressing vulnerabilities affecting Qualcomm products. The bulletin served as the primary source of remediation guidance referenced by subsequent advisories.

Veeam publishes Kasten for Kubernetes security advisory

On 2026-03-02, Veeam released a security advisory addressing vulnerabilities in multiple versions of Veeam Kasten for Kubernetes and Kasten K10 by Veeam. The vendor provided references to security fixes, improvements, and additional knowledge base details.

Feb 27, 20264mo ago

VMware releases Tanzu product security advisories

On 2026-02-27, VMware published security advisories for multiple Tanzu products, including Tanzu Greenplum, Greenplum Upgrade, Greenplum Backup and Restore, and Tanzu RabbitMQ on Kubernetes. The advisories identified fixed-version thresholds for several affected components.

Feb 23, 20264mo ago

Dell publishes multiple security advisories across product lines

Between 2026-02-23 and 2026-03-01, Dell released multiple advisories for vulnerabilities affecting products including PowerStore T Security, PowerEdge servers, and NVIDIA BlueField, ConnectX, and DOCA-related components. The advisories specified affected versions and directed customers to apply updates.

CISA issues multiple ICS security advisories

Between 2026-02-23 and 2026-03-01, CISA published several ICS advisories covering vulnerabilities in products such as EV charging platforms, industrial control software, building management systems, and IP cameras. The advisories identified affected vendors and versions and recommended mitigations and updates where available.

IBM publishes multiple product security advisories

Between 2026-02-23 and 2026-03-01, IBM published multiple security advisories affecting a broad range of products, including data platforms, middleware, automation, identity governance, storage management, and security monitoring offerings. The advisories provided remediation guidance and updates for affected systems.

Red Hat publishes multiple product security advisories

Between 2026-02-23 and 2026-03-01, Red Hat released security advisories covering vulnerabilities across multiple products, including the Linux kernel, Red Hat Enterprise Linux, and related variants. Users were advised to review the advisories and apply the relevant updates.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

29 LINKEDOpen in app
Affected products
7 linked
Samsung Mobile DevicesSamsung Mobile DevicesAndroidPowerstore TAndroidRed Hat Enterprise LinuxRed Hat Enterprise Linux Server
Organizations
22 linked
Samsung ElectronicsPelcoDell TechnologiesYokogawaJohnson ControlsRed HatNvidiaSchneider ElectricInternational Business MachinesMongodbVeeam SoftwareQualcommBroadcomCopelandGardynEV EnergyChargemapCloudchargeEv2goMobility46InsatSWTCH EV
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.