CVE-2026-25939Disclosure(frangoteam / fuxa)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch frangoteam fuxa systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, exposing connected ICS/SCADA environments to follow-on actions. This has been patched in FUXA version 1.2.11.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fuxa

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-10); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
fuxa

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-09: 1Mentions · 2026-02-10: 4Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-10: 2Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 4Technical Details · 2026-03-03: 102-0902-1003-03
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-091
Disclosure1
2026-02-104
Disclosure2Patch2
2026-03-031
Disclosure1
Full discourse6 posts
  • CCB Alert@CCBalert
    Patch

    Warning: multiple critical in #FUXA #SCADA #ICS CVE-2026-25939, CVE-2026-25893, CVE-2026-25894, CVE-2026-25895 & CVE-2026-25938 CVSS: 10.0-9.3 Network based attackers can cause full system compromise. Update to 1.2.11 or later https://github.com/frangoteam/FUXA/releases/tag/v1.2.11 #Patch #Patch #Patch

    Post summary

    Multiple critical CVEs in FUXA SCADA systems with CVSS 10.0-9.3 are announced; users are urged to update to v1.2.11 or later via the provided GitHub link.

    01000209
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25939 Authorization Bypass Vulnerability in FUXA SCADA Software Versions 1.2.8-1.2.10 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25939

    Post summary

    A new authorization bypass vulnerability (CVE-2026-25939) affecting FUXA SCADA Software v1.2.8-1.2.10 has been identified and reported, with details available on Vulmon.

    0001071
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25939 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows… https://www.cve.org/CVERecord?id=CVE-2026-25939

    Post summary

    The text announces an authorization bypass vulnerability in FUXA versions 1.2.8‑1.2.10, linking to the CVE record but providing no PoC, exploit, patch, or active exploitation details.

    00010229
    56.5K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-25939 (TIER 1) Critical auth bypass in FUXA (v1.2.8–1.2.10). The /api/schedulerendpoint allows unauthenticated POST/DELETE Attacker attractiveness: VERY HIGH DPI relevance: Critical Infrastructure (SCADA/HMI/ICS) Full analysis: https://lnkd.in/eSEmG23v

    Post summary

    A critical authentication bypass (CVE-2026-25939) in FUXA allows unauthenticated POST/DELETE requests to /api/schedulerendpoint, posing high risk to SCADA/HMI/ICS systems.

    0000055
    42 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: Unauthenticated remote attackers can bypass authorization in frangoteam FUXA (<1.2.11), risking industrial control! Patch now to protect SCADA/HMI systems. 🔒 https://radar.offseq.com/threat/cve-2026-25939-cwe-862-missing-authorization-in-fr-75e34d8a #OffSeq #ICS #S... https://t.co/Rbq6zgHbFj

    Post summary

    The tweet announces a critical authorization bypass vulnerability in frangoteam FUXA versions below 1.2.11 that could affect SCADA/HMI systems, urging immediate patching.

    0000040
    268 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25939: Ghost in the Machine: Unrestricted Guest Access in FUXA SCADA A critical authorization bypass vulnerability in FUXA SCADA software (versions 1.2.8 - 1.2.10) allows unauthenticated attackers to obtain 'Guest' privileges and subsequently... https://cvereports.com/reports/CVE-2026-25939

    Post summary

    The text announces a critical authorization bypass in FUXA SCADA (CVE-2026-25939) that lets unauthenticated attackers obtain Guest privileges, with no PoC, exploit, or patch details provided.

    0000068
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrangoteamfuxa---

Explore more