DFIR Radar[verified]@DFIR_RadarDisclosure
The text announces a new vulnerability (CVE‑2026‑25895) in FUXA 1.2.9, detailing the lack of authentication on /api/upload, path‑traversal via the destination parameter, and multiple RCE vectors, but it does not provide a PoC, tool, active exploitation claim, or patch information.
OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqPatch
The tweet highlights CVE‑2026‑25895 in frangoteam FUXA (<1.2.10), which allows unauthenticated file write, and urges immediate patching to mitigate the high risk to SCADA/HMI systems.
pdnuclei-bot@pdnuclei_botDisclosure
The CVE-2026-25895 vulnerability affects FUXA versions up to 1.2.9, enabling unauthenticated path traversal for arbitrary file writes, with details provided via a ProjectDiscovery reference.
CyberTLDR@CyberTLDRActive Exploitation
The tweet reports that two critical open‑source vulnerabilities (CVE‑2026‑64849 and CVE‑2026‑25895) are being actively exploited, but it does not mention any patch or exploit code.
CCB Alert@CCBalertPatch
The message is a patch advisory warning users of multiple critical CVEs in FUXA SCADA/ICS and urges updating to version 1.2.11 or later.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The entry references CVE-2026-25895 as an unauthenticated path traversal issue in FUXA Web-Based SCADA Software, but offers no further details on PoC, exploitation, or remediation.
CVE@CVEnewDisclosure
A path traversal vulnerability in FUXA permits unauthenticated remote attackers to write files, but no evidence of exploitation or mitigations is presented.