CVE-2026-22553Disclosure(insat / masterscada)

LOWCVSS 9.3 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • masterscada

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-02-25)
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
masterscada

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-02-24: 2Mentions · 2026-02-25: 4Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 402-2402-25
Signal classification1 categories
Disclosure
6100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure2
2026-02-254
Disclosure4
Full discourse6 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-22553 All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerab… https://www.cve.org/CVERecord?id=CVE-2026-22553 ----- Traducción: CVE-2026-22553 Tod… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-22553, noting OS command injection in InSAT MasterSCADA BUK-TS via a web interface field, but provides no PoC, exploit, or patch details.

    0000036
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22553 All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerab… https://www.cve.org/CVERecord?id=CVE-2026-22553

    Post summary

    CVE-2026-22553 exposes an OS command injection flaw in the MMadmServ web interface of InSAT MasterSCADA BUK-TS, allowing malicious users to execute arbitrary commands.

    00000289
    56.6K followersView on X
  • Kernyx64@kernyx64
    Disclosure

    24/02/2026 🚨 Critical vulnerabilities in InSAT MasterSCADA BUK-TS could allow remote code execution via SQL and OS command injection (CVE-2026-21410, CVE-2026-22553). Affected users must take immediate action to mitigate risks. https://www.cisa.gov/news-events/ics-advisories/icsa-26-055-01

    Post summary

    The advisory announces critical RCE vulnerabilities in InSAT MasterSCADA BUK-TS, urging users to act promptly, but no PoC, exploit, or patch details are provided.

    0000040
    27 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22553 OS Command Injection Vulnerability in InSAT MasterSCADA BUK-TS Web Interface https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22553

    Post summary

    A new OS command injection vulnerability (CVE-2026-22553) has been identified in the InSAT MasterSCADA BUK-TS web interface, with details available on Vulmon.

    0000048
    4.0K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-22553** pertains to all versions of **InSAT MasterSCADA BUK-TS**, a supervisory control and data acquisition (SCADA) system used in industrial control environments. The vulnerability allows **OS command injection** via a specific field in the web interface of the `MMadmServ` component. This flaw enables an attacker to execute arbitrary system commands remotely, leading to potential full system compromise. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #Apple https://cvetodo.com/cve/CVE-2026-22553

    Post summary

    The post announces CVE-2026-22553, an OS command injection flaw in InSAT MasterSCADA BUK-TS that allows remote command execution, but provides no PoC, exploit, or patch information.

    0000044
    20 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: CVE-2026-22553 in InSAT MasterSCADA BUK-TS allows unauthenticated RCE via MMadmServ web interface. All versions affected — patch unavailable. Restrict access & monitor now! https://radar.offseq.com/threat/cve-2026-22553-cwe-78-in-insat-masterscada-buk-ts-da2080e7 #... https://t.co/lk0eYwRxua

    Post summary

    A critical CVE‑2026‑22553 vulnerability in InSAT MasterSCADA BUK‑TS allows unauthenticated remote code execution via the MMadmServ web interface, with no patch available and no PoC or exploit disclosed.

    0000051
    269 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appinsatmasterscada---

Explore more