CVE-2026-4436Disclosure

LOWCVSS 8.6 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas line.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-04-09); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-15: 1Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1Active Exploitation · 2026-04-09: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 104-0904-1504-1904-21
Signal classification3 categories
Disclosure
466.7%
Active Exploitation
116.7%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-093
Active Exploitation1Disclosure2
2026-04-151
General1
2026-04-191
Disclosure1
2026-04-211
Disclosure1
Full discourse6 posts
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2026-4436: GPL Odorizers GPL750 Unauthenticated Modbus Exploitation — Detec… "CVE-2026-4436 (CVSS 8.6) allows unauthenticated manipulation of gas odorant…" 🔗 https://securityarsenal.com/blog/cve-2026-4436-gpl-odorizers-gpl750-unauthenticated-modbus-exploitation-detection-and-defense #CyberSecurity #ThreatIntel #alerttriage #alertfatigue #socautomation

    Post summary

    The tweet announces CVE‑2026‑4436, providing its CVSS score and describing unauthenticated Modbus exploitation of GPL Odorizers GPL750; it links to a blog for detection and defense but offers no PoC, exploit, or patch details.

    0000051
    11 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Disclosure

    🚨 HIGH severity CVE-2026-4436 (CVSS 8.6) Modbus vulnerability allows unauthenticated remote attackers to manipulate odorant injection systems in gas infrastructure. No privileges required. CWE-306: Missing Authentication #CVE #Vulnerability #PatchNow #ICS https://t.co/ndrzjrMkM4

    Post summary

    Tweet announces a high‑severity CVE‑2026‑4436 Modbus vulnerability (CVSS 8.6) that permits unauthenticated remote manipulation of odorant injection systems in gas infrastructure, with no privileges required and identified as CWE‑306.

    0000052
    26 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity CVE-2026-4436: GPL Odorizers GPL750 Remote Manipulation — Defense and Remediati… "A critical vulnerability has been identified in GPL Odorizers GPL750 systems,…" 🔗 https://securityarsenal.com/blog/cve-2026-4436-gpl-odorizers-gpl750-remote-manipulation-defense-and-remediation #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    The tweet alerts to CVE-2026-4436, a critical remote manipulation flaw in GPL Odorizers GPL750, and links to a blog post for further details, but it provides none of the technical or actionable information typically needed for deeper analysis.

    0000028
    10 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4436: HIGH] Remote attackers can manipulate Modbus packets to alter gas odorant injection, endangering systems. Stay alert for cyber threats in critical infrastructure.#cve,CVE-2026-4436,#cybersecurity https://cvefind.com/CVE-2026-4436

    Post summary

    The message announces a newly disclosed CVE (CVE‑2026‑4436) identified as HIGH severity, noting that attackers can alter Modbus packets to manipulate gas odorant injection, but provides no evidence of exploitation, PoC, or mitigation.

    0000055
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4436 A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little… https://www.cve.org/CVERecord?id=CVE-2026-4436

    Post summary

    The message announces CVE‑2026‑4436, noting that a low‑privileged remote attacker can send Modbus packets to manipulate register values affecting odorant injection logic, but it provides no PoC, exploit code, active exploitation evidence, or patch information.

    00000108
    57.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited CVE-2026-4436 to send unauthorized Modbus commands to GPL750 odorizer devices, manipulating odorant injection levels in gas pipelines. The missing authentication flaw enabled potential lateral movement across industrial networks. Runtime segmentation could help limit blast radius in OT environments. 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/gpl-odorizers-gpl750-vulnerability-2026 #Vulnerability #OTSecurity

    Post summary

    The post reports active exploitation of CVE‑2026‑4436 on GPL750 odorizer devices via unauthorized Modbus commands, highlighting a missing authentication flaw, but it offers no patch, workaround, or PoC details.

    0000042
    1.9K followersView on X

Explore more