CVE-2026-19656Disclosure(scada-lts / scada-lts)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • scada-lts

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
scada-lts

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-13: 2PoC Mentioned / Linked · 2026-08-13: 1Technical Details · 2026-08-13: 108-13
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • ExploitGrid@exploitgrid
    Disclosure

    [CVE] CVE-2026-19656 [HIGH PRIORITY] #ScadaLTS Authenticated Remote Code Execution 🔗 https://exploitgrid.net/cve/CVE-2026-19656

    Post summary

    The tweet announces CVE-2026-19656 as a high‑priority authenticated remote code execution vulnerability in ScadaLTS and points to an external exploit resource.

    1000026
    30 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2024-27253 CVE-2026-67282 CVE-2026-73299 CVE-2026-16860 CVE-2026-19656 ..🧵👇

    Post summary

    The post lists several CVEs without providing further technical details, exploitation status, patches, or proofs of concept.

    1000043
    30 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appscada-ltsscada-lts2.7.8.1--

Explore more