CVE-2026-14950Disclosure

LOWCVSS 9.2 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-20: 4Patch / Workaround · 2026-08-20: 2Technical Details · 2026-08-20: 408-20
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Full discourse4 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Frauscher FDS102 vulnerabilities include CVE-2026-14950 (CVSS 9.8), a session flaw enabling unauthorized continued access. Update to v2.14.0. #Frauscher #FDS102 #ICS #RailwaySecurity #CVE #OTSecurity https://securityonline.info/frauscher-fds102-vulnerabilities/

    Post summary

    The post reports a high‑severity CVE‑2026‑14950 in Frauscher FDS102, describes it as a session flaw that permits unauthorized continued access, and announces that a patch (v2.14.0) is available.

    01010448
    12.9K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-14950 — CVSS 9.8/10 ██████████ An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/vambS0Hv11

    Post summary

    The tweet announces CVE-2026-14950 as a critical vulnerability with a CVSS score of 9.8/10 and urges users to apply the available patch.

    1000065
    69 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-14950 Session Hijacking Risk in FDS Web Interface After Expiration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-14950

    Post summary

    The link points to a disclosure of a session hijacking risk affecting the FDS web interface after session expiration, with no evidence of exploitation, PoC, or patch information provided.

    0000098
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14950 An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the … https://www.cve.org/CVERecord?id=CVE-2026-14950

    Post summary

    A short disclosure of CVE-2026‑14950 describing session reuse after expiry, with no evidence of active exploitation, PoC, or patch information.

    00000772
    58.0K followersView on X

Explore more