Authorization Bypass in FUXA SCADA/HMI Software by Frango Team
CVE-2026-25939
9.3CRITICAL
What is CVE-2026-25939?
The FUXA software, a web-based Process Visualization solution, is affected by an authorization bypass vulnerability that enables remote attackers, without authentication, to create and modify arbitrary schedulers. This vulnerability poses significant risks to connected Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) environments by potentially allowing unauthorized manipulation of critical scheduling functions. Users are encouraged to update to version 1.2.11, where the vulnerability has been patched.
Affected Version(s)
FUXA < 1.2.11
