PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-6284 Horner Automation CVE debrief

CVE-2026-6284 is a critical authentication weakness affecting Horner Automation Cscape and XL4/XL7 PLC products. CISA says an attacker with network access to the PLC can brute-force passwords because of limited password complexity and the lack of password input limiters, which can lead to unauthorized access to systems and services. The published remediation is to update Cscape to v10.2 SP2 or later and install the latest firmware for the affected PLCs.

Vendor
Horner Automation
Product
Cscape
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-16
Original CVE updated
2026-04-16
Advisory published
2026-04-16
Advisory updated
2026-04-16

Who should care

OT/ICS operators, PLC administrators, and engineering teams running Horner Automation Cscape v10.0, XL4 PLC v16.32.0, or XL7 PLC v15.60 should treat this as urgent, especially if PLC management or authentication services are reachable from the network.

Technical summary

The source advisory describes a network-reachable password enumeration/brute-force condition caused by limited password complexity and no password input limiters. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, indicating easy remote exploitation with high confidentiality and integrity impact and no availability impact in the scoring model.

Defensive priority

Immediate

Recommended defensive actions

  • Update Horner Automation Cscape to v10.2 SP2 or later.
  • Apply the latest firmware for both XL4 and XL7 PLCs.
  • Restrict network access to affected PLC interfaces and management services to only trusted administrative sources.
  • Use OT network segmentation and defense-in-depth controls to reduce exposure of PLC authentication surfaces.
  • Review logs and alerting for repeated or suspicious authentication attempts.
  • Consult Horner Automation release notes and CISA ICS recommended practices for deployment-specific guidance.

Evidence notes

This debrief is based on the supplied CISA CSAF advisory ICSA-26-106-02 and the official CVE record metadata in the corpus. The advisory text explicitly states that an attacker with network access can brute-force discover passwords because of limited password complexity and no password input limiters, and it lists vendor remediation to update Cscape and PLC firmware. Published and modified dates in the corpus are both 2026-04-16T06:00:00.000Z.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-6284 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-6284

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-6284 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6284

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-106-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-106-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.