CVE-2026-24790Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-02-20: 4Technical Details · 2026-02-20: 402-20
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-24790 The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication. https://www.cve.org/CVERecord?id=CVE-2026-24790

    Post summary

    The message announces CVE-2026-24790, informing that a device’s PLC can be manipulated remotely due to missing authentication safeguards, offering no remediation or exploit details.

    00001143
    56.4K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    A critical missing-authentication vulnerability (CVE-2026-24790) in Welker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller may cause unauthorized odorization events. CISA rates it CVSS 8.2. #IndustrialControl #CISA #USA https://ift.tt/Zbcu3xd

    Post summary

    A missing-authentication vulnerability (CVE-2026-24790) has been disclosed in the Welker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller, rated CVSS 8.2 by CISA.

    0001077
    3.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-24790 - High The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication. https://www.thehackerwire.com/vulnerability/CVE-2026-24790/ https://t.co/KieI0UJpWi

    Post summary

    The post announces CVE‑2026‑24790, highlighting remote influence of a PLC lacking authentication, without mentioning exploitation, patches, or a PoC.

    0000039
    112 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-24790** pertains to a security flaw in the programmable logic controller (PLC) of a device, where an attacker can remotely influence the device's PLC without requiring authentication or proper safeguards. The vulnerability allows an attacker to manipulate the PLC's behavior over the network, potentially leading to malicious control of industrial processes. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #Apple https://cvetodo.com/cve/CVE-2026-24790

    Post summary

    The tweet announces CVE‑2026‑24790, a high‑severity PLC flaw that allows unauthenticated remote manipulation of industrial processes, with no patches, PoC, or active exploitation mentioned.

    0000028
    20 followersView on X

Explore more