CVE-2026-21718Disclosure(copeland / xweb_300d_pro)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch copeland xweb_300d_pro systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution on the system.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xweb_300d_pro
  • xweb_300d_pro_firmware
  • xweb_500b_pro
  • xweb_500b_pro_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-27); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
xweb_300d_proxweb_300d_pro_firmwarexweb_500b_proxweb_500b_pro_firmwarexweb_500d_proxweb_500d_pro_firmware

1 version affected across 6 products

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-27: 4Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Active Exploitation · 2026-02-27: 1Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-27: 4Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 102-2703-0303-04
Signal classification2 categories
Disclosure
583.3%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-274
Active Exploitation1Disclosure3
2026-03-031
Disclosure1
2026-03-041
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-21718 (CVSS:10.0, CRITICAL) is Analyzed. An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to ..https://nvd.nist.gov/vuln/detail/CVE-2026-21718 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical authentication bypass vulnerability (CVE-2026-21718) affecting Copeland XWEB Pro 1.12.1 and earlier, with CVSS 10.0, but provides no PoC, exploit, or patch details.

    1000048
    173 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Active Exploitation

    🚨 CRITICAL: Copeland XWEB 300D PRO flaw lets attackers bypass authentication & run code remotely — no user action needed! Used in industrial control systems. Patch unavailable — segment & monitor now. https://radar.offseq.com/threat/cve-2026-21718-cwe-327-in-copeland-copeland-... https://t.co/X4SjYQSv30

    Post summary

    A critical flaw in Copeland XWEB 300D PRO allows attackers to bypass authentication and execute code remotely without user action, and it is reportedly being used in industrial control systems. No patch is available, so operators should segment and monitor affected devices.

    0001047
    270 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-21718 (CVSS:10.0, CRITICAL) is Analyzed. An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to ..https://nvd.nist.gov/vuln/detail/CVE-2026-21718 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical authentication bypass vulnerability (CVE‑2026‑21718) in Copeland XWEB Pro (v1.12.1 and earlier) with CVSS 10.0, linking to the NVD entry for details.

    0000022
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21718 An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and ach… https://www.cve.org/CVERecord?id=CVE-2026-21718

    Post summary

    The post announces an authentication bypass flaw in Copeland XWEB Pro 1.12.1 and earlier versions, providing the CVE ID and a link to the official record without indicating active exploitation or mitigation.

    00000148
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-21718: CRITICAL] Copeland XWEB Pro v1.12.1 & earlier contains an authentication bypass flaw. Attackers can skip auth & execute code pre-auth. #CyberSecurity#cve,CVE-2026-21718,#cybersecurity https://cvefind.com/CVE-2026-21718

    Post summary

    The tweet announces a critical authentication bypass vulnerability in Copeland XWEB Pro (v1.12.1 and earlier) that permits code execution before authentication.

    0000039
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-21718** describes a critical authentication bypass vulnerability in **Copeland XWEB Pro version 1.12.1 and earlier**. This flaw allows an attacker to bypass the authentication mechanism entirely, leading to pre-authenticated code execution on the affected system. Because no authentication is required, an attacker can exploit this remotely over the network without prior access or user interaction. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #AuthBypass #Apple https://cvetodo.com/cve/CVE-2026-21718

    Post summary

    CVE-2026-21718 is a critical authentication bypass in Copeland XWEB Pro that enables unauthenticated remote code execution. No PoC, exploit, patch, or active exploitation information is provided.

    0000037
    20 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
HWcopelandxweb_300d_pro---
OScopelandxweb_300d_pro_firmware---
HWcopelandxweb_500b_pro---
OScopelandxweb_500b_pro_firmware---
HWcopelandxweb_500d_pro---
OScopelandxweb_500d_pro_firmware---

Explore more