CVE-2026-25893Disclosure(frangoteam / fuxa)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch frangoteam fuxa systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the heartbeat refresh API and execute arbitrary code on the server. This issue has been patched in FUXA version 1.2.10.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fuxa

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-10)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
fuxa

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-09: 1Mentions · 2026-02-10: 3Patch / Workaround · 2026-02-10: 2Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 302-0902-10
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-091
Disclosure1
2026-02-103
Disclosure1Patch2
Full discourse4 posts
  • CCB Alert@CCBalert
    Patch

    Warning: multiple critical in #FUXA #SCADA #ICS CVE-2026-25939, CVE-2026-25893, CVE-2026-25894, CVE-2026-25895 & CVE-2026-25938 CVSS: 10.0-9.3 Network based attackers can cause full system compromise. Update to 1.2.11 or later https://github.com/frangoteam/FUXA/releases/tag/v1.2.11 #Patch #Patch #Patch

    Post summary

    The post alerts users to several critical CVEs in FUXA SCADA/ICS and recommends updating to version 1.2.11 or later via the provided GitHub release link to mitigate the vulnerabilities.

    01000209
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25893 Authentication Bypass in FUXA SCADA Software Enables Remote Code Executi... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25893 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new authentication bypass vulnerability (CVE‑2026‑25893) in FUXA SCADA software that permits remote code execution has been announced, but no PoC, exploitation details, or patch information are provided.

    0001091
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25893 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, r… https://www.cve.org/CVERecord?id=CVE-2026-25893

    Post summary

    The post discloses an authentication bypass flaw in FUXA (pre‑1.2.10) that permits unauthenticated access, but it provides no PoC, exploit, or patch details.

    00010204
    56.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: frangoteam FUXA <1.2.10 has an auth bypass bug — remote attackers can get admin & run code via the heartbeat API. Patch now to protect SCADA/HMI systems! https://radar.offseq.com/threat/cve-2026-25893-cwe-285-improper-authorization-in-f-a5914f35 #OffSeq #ICS #Vulne... https://t.co/tIn2eiOzuu

    Post summary

    A critical authentication bypass in frangoteam FUXA (<1.2.10) lets attackers gain admin rights and execute code via the heartbeat API; immediate patching is urged for SCADA/HMI systems.

    0000043
    268 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrangoteamfuxa---

Explore more