Cross-Site Scripting Vulnerability in Microchip TimePictra
CVE-2026-3010

9.3CRITICAL

Key Information:

Vendor

Microchip

Vendor
CVE Published:
28 February 2026

What is CVE-2026-3010?

An issue has been identified in Microchip TimePictra, where improper handling of input during web page generation may lead to a Cross-Site Scripting (XSS) vulnerability. This allows attackers to inject malicious scripts into web pages viewed by users, potentially compromising the confidentiality and integrity of sensitive data. The vulnerability affects multiple versions of TimePictra, specifically from 11.0 through 11.3 SP2. Users are advised to apply the recommended security patches to mitigate this threat. For detailed information and reporting potential vulnerabilities, visit Microchip's official advisory page.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

TimePictra 11.0 <= 11.3 SP2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Steve Lin
Bastion Security
.