CVE-2026-1358Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 11 signals
  • Disclosure: 7 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-16); latest day: 2
  • 11 total mentions across 5 days

Deep dive

Activity timeline11 mentions / 5d
01234Mentions · 2026-02-12: 3Mentions · 2026-02-13: 1Mentions · 2026-02-15: 1Mentions · 2026-02-16: 4Mentions · 2026-02-17: 2PoC Mentioned / Linked · 2026-02-15: 1PoC Mentioned / Linked · 2026-02-16: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-16: 2Technical Details · 2026-02-12: 3Technical Details · 2026-02-13: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-16: 4Technical Details · 2026-02-17: 202-1202-1302-1502-1602-17
Signal classification2 categories
Disclosure
763.6%
Patch
436.4%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-123
Disclosure2Patch1
2026-02-131
Patch1
2026-02-151
Disclosure1
2026-02-164
Disclosure2Patch2
2026-02-172
Disclosure2
Full discourse11 posts
  • Gray Hats@the_yellow_fall
    Patch

    CISA warns of critical Airleader Master vulnerability CVE-2026-1358. Unauthenticated attackers can upload files and gain RCE. Update to 6.386 now. #Airleader #ICS #OTSecurity #CyberSecurity #CVE20261358 #CriticalInfrastructure #RCE https://securityonline.info/industrial-sabotage-risk-critical-airleader-flaw-cvss-9-8-exposed/

    Post summary

    CISA warns of a critical CVE-2026-1358 in Airleader Master that allows unauthenticated file uploads leading to RCE, and advises updating to version 6.386.

    02072557
    10.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1358 Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthentica… https://www.cve.org/CVERecord?id=CVE-2026-1358

    Post summary

    The post announces CVE‑2026‑1358, noting that Airleader Master 6.381 and earlier versions allow unrestricted file uploads to webpages running at maximum privileges, potentially permitting unauthenticated attacks.

    00020376
    56.5K followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    Critical vulnerability CVE-2026-1358 in Airleader Master allows remote code execution. Immediate action required to secure industrial systems. https://thedailytechfeed.com/critical-ics-flaw-in-airleader-master-puts-industrial-sectors-at-risk-of-remote-code-execution/ #Cybersecurity #ICS #Vulnerability #Security #Industrial #Remote #Execution #Technology #Software #Patch #Update #Risk #Threat #Protection #Defense #Alert #Network #Breach #Mitigation #Urgent

    Post summary

    CVE-2026-1358 is a remote code execution flaw in Airleader Master; no PoC, exploit tool, or evidence of active exploitation is reported, and no patch or workaround is mentioned, but immediate action is urged.

    0000039
    222 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    CISA discloses critical Airleader ICS flaw CVE-2026-1358, CVSS 9.8, affecting all versions and enabling remote code execution across multiple critical infrastructure sectors. #ICS https://threatcluster.io/cluster/critical-airleader-vulnerability-enables-remote-code-executi-408a7e39

    Post summary

    CISA discloses a critical remote code execution vulnerability (CVE-2026-1358) with a CVSS score of 9.8, impacting all Airleader versions across multiple critical infrastructure sectors.

    0000047
    71 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 Critical Unrestricted File Upload Flaw in Airleader Master (#CVE-2026-1358): Remote Root Exploit Exposes ICS/SCADA Networks https://undercodetesting.com/critical-unrestricted-file-upload-flaw-in-airleader-master-cve-2026-1358-remote-root-exploit-exposes-ics-scada-networks/ Educational Purposes!

    Post summary

    A new critical vulnerability (CVE-2026-1358) in Airleader Master allows unrestricted file uploads that can lead to remote root access; the linked article presumably contains a PoC, but no patch or active exploitation is reported.

    0000051
    387 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Critical Airleader Master RCE (CVE-2026-1358, CVSS 9.8) Puts ICS Monitoring Deployments at Risk CISA warns Airleader Master ≤ 6.381 is vulnerable to an unrestricted file upload flaw (ICSA-26-043-10) that could let unauthenticated attackers achieve remote code execution on exposed systems. This matters because Airleader is used across multiple critical-infrastructure sectors, so an internet-facing instance can become an IT/OT pivot and enable disruptive operations. 🎯 Target: Global/ICS-OT (Critical Infrastructure) #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cybersecuritynews.com/airleader-vulnerability/

    Post summary

    CISA warns that Airleader Master versions ≤6.381 are vulnerable to an unrestricted file upload flaw (CVE‑2026‑1358, CVSS 9.8), enabling unauthenticated remote code execution and posing a risk to critical infrastructure.

    0000042
    176 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical Airleader Master Unrestricted File Upload Bug Enables Pre-Auth RCE in ICS Environments CISA disclosed CVE-2026-1358 (CVSS 9.8): Airleader Master ≤ 6.381 allows unrestricted file uploads across privileged web pages, enabling unauthenticated attackers to upload a malicious file and achieve remote code execution on the server. This matters because Airleader deployments span multiple critical-infrastructure sectors, so exposed instances can become an IT/OT pivot point—upgrade to ≥ 6.386 and ensure the system isn’t internet-facing. 🎯 Target: Global/ICS-OT (Critical Infrastructure) #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cyberpress.org/critical-airleader-flaw-exposes-systems-to-remote-code-execution-attacks/

    Post summary

    CISA reports a critical RCE vulnerability (CVE-2026-1358) in Airleader Master allowing unauthenticated file uploads; users are advised to upgrade to ≥6.386 or remove internet exposure.

    0000045
    176 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1358: Airleader Master Unrestricted Upl... Unrestricted file uploads in Airleader Master creates trivial RCE path for unauthenticated attackers - max privileges wi... https://zerodaysignal.com/vulnerability/CVE-2026-1358 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑1358, highlighting an unrestricted file upload flaw that allows unauthenticated attackers to execute arbitrary code with maximum privileges, and provides a link to further details.

    0000079
    131 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    ⚠️ CRITICAL: Airleader Master flaw (CVE-2026-1358) lets unauthenticated attackers upload files & execute code. Industrial systems in EU at high risk! Patch ASAP, restrict uploads, segment networks. https://radar.offseq.com/threat/cve-2026-1358-cwe-434-in-airleader-gmbh-airlead... https://t.co/jwtd6Cn9H9

    Post summary

    The post reports a critical flaw (CVE-2026-1358) that permits unauthenticated file uploads and code execution on Airleader Master, urging immediate patching and network segmentation.

    0000073
    268 followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Disclosure

    CVE-2026-1358 i Airleader Master tillåter obehöriga att ladda upp filer och kan leda till fjärrkodexekvering. Allvarliga risker för systemets säkerhet kräver omedelbara åtgärder. #säkerhet #cybersäkerhet #CVE

    Post summary

    The CVE-2026-1358 vulnerability in Airleader Master permits unauthenticated file uploads that could lead to remote code execution, requiring immediate remediation.

    0000036
    7 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 CISA warns Airleader Master flaw enables remote code execution on compressor-control systems CISA released ICS Advisory ICSA-26-043-10 (Feb 12, 2026) warning that Airleader Master (≤ 6.381) is affected by CVE-2026-1358, where successful exploitation could allow remote code execution—putting industrial compressed-air management environments at risk if systems are exposed. Apply vendor fixes/mitigations and restrict remote access to the controller interfaces. 🎯 Target: Global/Industrial (Manufacturing/Utilities – Compressed Air Systems) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-10

    Post summary

    CISA issues a warning that Airleader Master is vulnerable to CVE‑2026‑1358, enabling remote code execution, and recommends applying vendor patches and restricting remote access.

    0000042
    191 followersView on X

Explore more