ScadaLTS 2.7.8.1 contains a reflected cross-site scripting vulnerability. The CVE record was published on 2026-08-12T20:17:43.060Z and has not been modified since then. Organizations should review and prioritize patching of affected ScadaLTS deployments, focusing on internet-exposed systems and those with high-priority operational roles. The vulnerability allows an unauthenticated attacker to execute arbi [truncated]
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process, leading to full compromise of the underlying system. The vulnerability's critical severity and potential impact necessitate immediate attent [truncated]