CVE-2026-95250

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Referenced assets3 URLs
By indicator
Full discourse1 post
  • Exploit-Garbage@RemotelyFreely

    Five more CVE IDs are in. MITRE assigned CVE-2026-95248 and CVE-2026-95250 through CVE-2026-95253 to five findings we published in batch #11 — SCADA/HMI, graph analytics, document viewing and data-centre console management. All five were found, verified and disclosed by our AI-driven research pipeline, public with full root-cause analysis and a working PoC from day one: CVE-2026-95248 — TigerGraph Community Edition 4.2.4 (CVSS 9.8) Ships the tigergraph/tigergraph pair with no forced rotation, and the login response itself recommends changing it. One HTTP call installs a GSQL query whose PRINT TO_CSV writes a file where you say, and the query endpoint answers with no session at all — so write authorized_keys and take an SSH shell into the graph analytics platform. CVE-2026-95250 — Ecava IntegraXor IGX 16.0.701.10 (9.8, pre-auth) The dxweb service on 8081 exposes POST /FileUpload with no authentication and a copyTo destination you control. dxmanager then reads every JSON file in the config directory and trusts http://meta.name without sanitization. Web SCADA HMI in manufacturing OT — unauthenticated upload to command execution. CVE-2026-95251 — Accusoft / Apryse PrizmDoc for Java, VirtualViewer 5.22.1 (9.8) POST /virtualviewer/AjaxServlet?action=uploadDocument takes your bytes with no cookie, no Authorization header and no credentials, and the on-disk filename comes from your filename parameter through a sanitizer that only strips path components. Upload a JSP into the served sample-documents directory and the container compiles it for you, running as uid 0. CVE-2026-95252 — LCDS Laquis SCADA (9.8, pre-auth) mili.exe, the web server on TCP 11234, performs no authentication check at all when no password is configured. POST /uploade.html writes any file anywhere with no content, filename or destination validation, and GET /reset.html restarts the process — also unauthenticated. The process that autoloads your DLL is the same one hosting Modbus TCP. CVE-2026-95253 — Opengear NGCS 25.11.8 (8.8, authenticated admin to root) POST /api/v2/pdus accepts a JSON http://pdu.name with no character filter, and commands/PDUs.lua carries it into io.popen — /bin/sh -c on the console manager that sits in front of every other device in the rack. A quoting helper exists elsewhere in the same code tree; this path never calls it. That brings the total to sixteen CVE IDs assigned to this project's research. Four of the five are pre-authentication; four score 9.8. Full writeups + PoCs: https://0day-rubbish.com/blog #CVE #0day #RCE #infosec #cybersecurity #SCADA #ICS #TigerGraph #Opengear

    0000049
    133 followersView on X

Explore more