CVE-2026-21410Disclosure(insat / masterscada)

LOWCVSS 9.3 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch insat masterscada systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • masterscada

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-02-25)
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
masterscada

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-02-24: 1Mentions · 2026-02-25: 5Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 502-2402-25
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-241
Disclosure1
2026-02-255
Disclosure4Patch1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-21410 InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potentially able to caus… https://www.cve.org/CVERecord?id=CVE-2026-21410

    Post summary

    CVE-2026-21410 exposes a SQL injection flaw in InSAT MasterSCADA BUK-TS’s main web interface, potentially allowing malicious users to exploit the system.

    00000112
    56.6K followersView on X
  • mysocAi@MysocAi
    Disclosure

    [CRITICAL] CVE-2026-21410: Critical SQL Injection in InSAT MasterSCADA BUK-TS CVE-2026-21410 allows SQL injection in InSAT MasterSCADA BUK-TS, potentially leading to remote code execution. CVE: CVE-2026-21410 • APT: U… https://www.thehackerwire.com/vulnerability/CVE-2026-21410/

    Post summary

    A critical SQL injection vulnerability (CVE-2026-21410) in InSAT MasterSCADA BUK-TS is disclosed, potentially enabling remote code execution.

    000001
    3 followersView on X
  • Kernyx64@kernyx64
    Disclosure

    24/02/2026 🚨 Critical vulnerabilities in InSAT MasterSCADA BUK-TS could allow remote code execution via SQL and OS command injection (CVE-2026-21410, CVE-2026-22553). Affected users must take immediate action to mitigate risks. https://www.cisa.gov/news-events/ics-advisories/icsa-26-055-01

    Post summary

    The advisory announces two critical CVEs in InSAT MasterSCADA BUK‑TS that enable remote code execution via SQL and OS command injection, urging users to act promptly.

    0000040
    27 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-21410 SQL Injection in InSAT MasterSCADA BUK-TS Enabling Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21410

    Post summary

    The post announces a SQL injection vulnerability (CVE-2026-21410) in InSAT MasterSCADA BUK-TS that can lead to remote code execution, with no PoC, exploit, or patch details provided.

    0000039
    4.0K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: All InSAT MasterSCADA BUK-TS versions vulnerable to unauthenticated SQL Injection (CVSS 9.8). Remote code execution & OT risk! Restrict access now, patch ASAP. https://radar.offseq.com/threat/cve-2026-21410-cwe-89-in-insat-masterscada-buk-ts-10cd43d6 #OffSeq #ICS #... https://t.co/fof4zuMfDn

    Post summary

    The tweet announces a critical unauthenticated SQL injection vulnerability in InSAT MasterSCADA BUK-TS, urging immediate patching to mitigate remote code execution risk.

    0000078
    270 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE ID:** CVE-2026-21410 **Product:** InSAT MasterSCADA BUK-TS **Vulnerability Type:** SQL Injection leading to Remote Code Execution (RCE) **Severity:** Critical (CVSS 3.1 Score: 9.8) **Attack Vector:** Network **Privileges Required:** None **User Interaction:** None **Scope:** Unchanged **Impact:** High on Confidentiality, Integrity, and Availability #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #SQLInjection https://cvetodo.com/cve/CVE-2026-21410

    Post summary

    The post announces a critical SQL injection vulnerability (CVE‑2026‑21410) in InSAT MasterSCADA BUK‑TS that can lead to remote code execution, but provides no proof‑of‑concept, exploit code, active exploitation evidence, or patch information.

    0000052
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appinsatmasterscada---

Explore more