CVE-2026-6284Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-521

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-17); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-16: 1Mentions · 2026-04-17: 2Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-17: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 2Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 104-1604-1704-1904-20
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-161
Disclosure1
2026-04-172
Disclosure2
2026-04-191
Disclosure1
2026-04-201
Disclosure1
Full discourse5 posts
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2026-6284: Horner Automation Cscape and PLCs Brute Force Vulnerability — De… "Critical CVSS 9.1 flaw in Horner XL4/XL7 PLCs allows password brute-forcing." 🔗 https://securityarsenal.com/blog/cve-2026-6284-horner-automation-cscape-and-plcs-brute-force-vulnerability-detection-and-hardening #CyberSecurity #ThreatIntel #alerttriage #alertfatigue #socautomation

    Post summary

    The post announces CVE-2026-6284, a CVSS 9.1 password brute‑force flaw affecting Horner Automation PLCs, but provides no PoC, active exploitation, patch details, or false‑positive claim.

    0000067
    11 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6284 An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexit… https://www.cve.org/CVERecord?id=CVE-2026-6284

    Post summary

    The post introduces CVE-2026-6284, noting attackers can brute-force passwords on PLCs due to limited complexity, but it lacks PoC, exploit code, patch info, or evidence of active exploitation.

    00000122
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6284 Brute Force Password Enumeration in PLC Systems via Network Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6284

    Post summary

    The post references CVE-2026-6284 and briefly describes it as a brute‑force password enumeration vulnerability in PLC systems, with no additional information on PoC, exploitation, patching, or active attacks.

    0000052
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-6284: Horner Automation Cs... Industrial PLCs with zero rate limiting + weak passwords = remote takeover via network brute force in minutes. #ICS #PLC #BruteForce. https://zerodaysignal.com/vulnerability/CVE-2026-6284 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-6284 exposes Horner Automation PLCs to remote takeover through brute force due to zero rate limiting and weak passwords, with a link likely holding more details. No patch info, active exploitation, or debunking claim is present.

    0000058
    218 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🚨 CVE-2026-6284 is the industrial version of “please don’t use password123.” Critical rating for brute-force + no lockout… because security is apparently optional. https://windowsforum.com/threads/horner-plc-flaw-cve-2026-6284-brute-force-password-risk-cvss-9-1-critical.413730/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #PlcVulnerabilities #IndustrialCybersecurity #CisaAdvisory #PasswordBruteForce https://t.co/odby8Wc18K

    Post summary

    The tweet announces CVE-2026-6284, a critical brute‑force flaw with no lockout in an industrial PLC, but provides no proof of concept, exploit code, or patch information.

    0000028
    1.1K followersView on X

Explore more