CVE-2026-71189

LOWCVSS 4.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-29: 109-29
Referenced assets1 URL
By indicator
Full discourse1 post
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — TOPTECH TMS7 / TOPHAT: TEN FLAWS REACH CVSS 10 AND CAN EXPOSE CRITICAL DATA OR ENABLE ARBITRARY CODE EXECUTION September 29, 2026 DISCLOSED BY: CISA ICS PRODUCT: Toptech TMS7 Toptech TopHAT CVE: CVE-2026-63713 CVE-2026-68068 CVE-2026-68954 CVE-2026-69662 CVE-2026-70356 CVE-2026-71189 CVE-2026-71302 CVE-2026-71379 CVE-2026-72507 CVE-2026-72510 AFFECTED VERSIONS: TMS7 7.6.3 TopHAT 7.6.3 IMPACT: CISA states successful exploitation of the vulnerability set could expose critical data or enable arbitrary code execution. The issues span multiple weakness classes, including externally accessible files/directories and insufficient restrictions around sensitive functionality. CVSS: Up to 10.0 Critical EXPLOITATION STATUS: VULNERABILITIES CONFIRMED NO CONFIRMED IN-THE-WILD EXPLOITATION IDENTIFIED Operational context: Toptech TMS7 is a terminal-automation/management platform used around fuel and liquid terminals and integrates with ERP and SCADA environments, increasing the potential operational impact of compromise. URGENT ACTION: Apply Toptech/CISA remediation, restrict TMS7/TopHAT management exposure, segment administrative access, and review exposed systems for unauthorized accounts, files, configuration changes, and abnormal activity. SOURCE: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02 #CyberSecurity #ThreatIntel #Toptech #ICS #OTSecurity #CriticalInfrastructure #CodeExecution #CVE

    0000033
    225 followersView on X

Explore more