CVE-2026-25938Disclosure(frangoteam / fuxa)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch frangoteam fuxa systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the Node-RED plugin is enabled. This has been patched in FUXA version 1.2.11.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fuxa

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-10); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
fuxa

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-09: 1Mentions · 2026-02-10: 4Mentions · 2026-02-12: 1PoC Mentioned / Linked · 2026-02-12: 1Patch / Workaround · 2026-02-10: 2Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 4Technical Details · 2026-02-12: 102-0902-1002-12
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
PoC
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-091
Disclosure1
2026-02-104
Disclosure2Patch2
2026-02-121
PoC1
Full discourse6 posts
  • CCB Alert@CCBalert
    Patch

    Warning: multiple critical in #FUXA #SCADA #ICS CVE-2026-25939, CVE-2026-25893, CVE-2026-25894, CVE-2026-25895 & CVE-2026-25938 CVSS: 10.0-9.3 Network based attackers can cause full system compromise. Update to 1.2.11 or later https://github.com/frangoteam/FUXA/releases/tag/v1.2.11 #Patch #Patch #Patch

    Post summary

    Multiple critical CVEs in FUXA SCADA with CVSS scores ranging from 10.0 to 9.3; updating to version 1.2.11 or later is advised to mitigate potential full system compromise.

    01000209
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25938 Authentication Bypass in FUXA 1.2.8-1.2.10 Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25938

    Post summary

    CVE-2026-25938 is an authentication bypass vulnerability in FUXA 1.2.8‑1.2.10 that allows remote code execution; no PoC, exploit, patch, or active exploitation details are provided.

    0001075
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25938 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthen… https://www.cve.org/CVERecord?id=CVE-2026-25938

    Post summary

    A new authentication bypass vulnerability (CVE‑2026‑25938) in FUXA’s web‑based process visualization software is disclosed, impacting versions 1.2.8 through 1.2.10.

    00010213
    56.5K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 #CVE-2026-25938 Deep Dive: FUXA SCADA Authentication Bypass Grants Unauthenticated RCE via Node-RED — PoC, Mitigation, and Hardening Walkthrough + Video https://undercodetesting.com/cve-2026-25938-deep-dive-fuxa-scada-authentication-bypass-grants-unauthenticated-rce-via-node-red-poc-mitigation-and-hardening-walkthrough-video/ Educational Purposes!

    Post summary

    The post presents a proof‑of‑concept for CVE‑2026‑25938, detailing an authentication bypass that yields unauthenticated RCE on Node‑RED, while also offering mitigation steps and a walkthrough video.

    0000067
    392 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    FUXA Server users should be aware of CVE-2026-25938, an unauthenticated RCE flaw in its Node-RED integration. Patching to version 1.2.11 or later is advised for affected systems. #FUXAServer #RCE #InfoSec https://www.pulsepatch.io/posts/cve-2026-25938-fuxa-server-unauthenticated-rce

    Post summary

    The post alerts users of CVE-2026-25938, an unauthenticated RCE in FUXA Server's Node-RED integration, and advises upgrading to version 1.2.11 or later to mitigate the flaw.

    0000044
    1 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25938: FUXA RCE: When the Dashboard Becomes a Command Prompt FUXA, a popular open-source SCADA/HMI dashboard, contained a critical authentication bypass in its Node-RED integration. By failing to verify JWT tokens on proxied routes, the softw... https://cvereports.com/reports/CVE-2026-25938

    Post summary

    CVE-2026-25938 exposes an authentication bypass in FUXA’s Node‑RED integration, allowing remote code execution by failing to validate JWT tokens on proxied routes.

    0000074
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrangoteamfuxa---

Explore more