PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40066 Anviz CVE debrief

CVE-2026-40066 affects Anviz CX2 Lite and CX7 devices. According to CISA’s advisory, an attacker can upload an unverified update package that the device unpacks and executes as a script, leading to unauthenticated remote code execution. The advisory was published on 2026-04-16 and assigns a CVSS 3.1 score of 8.8 (HIGH).

Vendor
Anviz
Product
CX2 Lite Firmware
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-16
Original CVE updated
2026-04-16
Advisory published
2026-04-16
Advisory updated
2026-04-16

Who should care

Operators, administrators, and security teams responsible for Anviz CX2 Lite and CX7 devices should treat this as a high-priority firmware risk. If CrossChex Standard is used to manage affected devices, it should be included in validation and mitigation planning.

Technical summary

CISA’s CSAF advisory states that CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device then unpacks and executes a script, which can result in unauthenticated remote code execution. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating network-reachable impact with high confidentiality, integrity, and availability consequences.

Defensive priority

High. This is a remotely reachable code-execution condition with severe impact, so affected environments should prioritize identification, containment, and vendor follow-up immediately.

Recommended defensive actions

  • Identify whether CX2 Lite or CX7 devices are deployed in your environment, including any systems managed through CrossChex Standard.
  • Restrict access to device management and update interfaces to trusted administrative networks only.
  • Monitor for unexpected firmware/update activity and review whether uploaded packages are being validated before installation.
  • Contact Anviz for remediation guidance using the vendor contact listed in the advisory.
  • Apply compensating controls from CISA ICS guidance, such as network segmentation and least-privilege administrative access, until a vendor fix is confirmed.

Evidence notes

This debrief is based on CISA advisory ICSA-26-106-03 and the corresponding CSAF source item, both published 2026-04-16. The source explicitly states that CX2 Lite and CX7 accept unverified update packages that can be uploaded and executed, resulting in unauthenticated remote code execution. The advisory also notes that Anviz did not respond to CISA’s coordination attempts. No exploit code or unverified remediation claims are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-40066 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-40066

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-40066 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40066

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-106-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-106-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.