CVE-2026-22553 is a critical command-injection vulnerability in InSAT MasterSCADA BUK-TS, affecting all versions. According to CISA, a malicious user interacting with the MMadmServ web interface may be able to inject operating-system commands and potentially achieve remote code execution. The advisory was publicly published on 2026-02-24.
CVE-2026-21410 is a critical SQL injection issue affecting InSAT MasterSCADA BUK-TS. According to the CISA CSAF advisory, the vulnerable main web interface may allow a malicious user to trigger remote code execution. Because the attack vector is network-accessible, requires no privileges, and has no user interaction requirement in the provided CVSS vector, this should be treated as an urgent remediation i [truncated]