CVE-2026-47717Disclosure

LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

1.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-08-13)
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-18: 1Mentions · 2026-06-19: 1Mentions · 2026-08-13: 2PoC Mentioned / Linked · 2026-06-18: 1Technical Details · 2026-06-18: 1Technical Details · 2026-06-19: 1Technical Details · 2026-08-13: 106-1806-1908-13
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-181
Disclosure1
2026-06-191
Disclosure1
2026-08-132
General2
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-47717 - high 🚨 FUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data Disclosure > FUXA v1.3.0 exposes full SCADA/HMI project configuration via GET /api/project without... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-47717 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post reports a high‑severity data disclosure (CVE‑2026‑47717) in FUXA 1.3.0 that lets unauthenticated users retrieve complete SCADA/HMI project configurations via a GET endpoint, and provides a link to a ProjectDiscovery library for detection.

    00011146
    959 followersView on X
  • NewNormal Security@NewScanTeam
    General

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 13 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 🔑 Config endpoint that hands out its session-signing key — anyone who can reach the port mints a valid session and reads every notebook (SiYuan CVE-2026-72793, CVE-2026-72794) 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🖥️ Unauthenticated SCADA/HMI project read — an anonymous request pulls the plant's screens and the addresses of every device behind them (FUXA CVE-2026-47717) ⚡ Sandbox escape in an AI agent builder — code runs on the host holding every model key and DB credential the flows use, and two of them need no login (Flowise CVE-2026-73483, CVE-2026-73485) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM

    Post summary

    NewNormal Security’s daily CVE report lists recent vulnerabilities in various applications, providing specific technical details but no exploit code, patch information, or active exploitation claims.

    0000045
    5 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-47717 Sensitive Project Data Exposure in FUXA Server 1.3.0 via API https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-47717

    Post summary

    The entry merely points to the CVE in a vulnerability database, with no actionable details, PoC, or exploitation information.

    00000127
    4.1K followersView on X
  • Halil Deniz@denizhalilT
    Disclosure

    🚨 CVE-2026-47717: Dive into my deep technical analysis of the FUXA SCADA API logic flaw that allows unauthenticated attackers to leak critical project configurations and operational data. Read the full analysis here: 👇 https://denizhalil.com/2026/06/19/cve-2026-47717-fuxa-scada-data-disclosure/ #SCADA #Infosec https://t.co/WJXtiuA0ya

    Post summary

    The tweet links to a detailed technical analysis of CVE-2026-47717, outlining a logic flaw that permits unauthenticated data leakage in the FUXA SCADA API, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000051
    31 followersView on X

Explore more