PatchSiren

SCADA-LTS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM SCADA-LTS CVE published 2026-08-12

CVE-2026-19657

ScadaLTS 2.7.8.1 contains a reflected cross-site scripting vulnerability. The CVE record was published on 2026-08-12T20:17:43.060Z and has not been modified since then. Organizations should review and prioritize patching of affected ScadaLTS deployments, focusing on internet-exposed systems and those with high-priority operational roles. The vulnerability allows an unauthenticated attacker to execute arbi [truncated]

CRITICAL SCADA-LTS CVE published 2026-08-12

CVE-2026-19656

ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process, leading to full compromise of the underlying system. The vulnerability's critical severity and potential impact necessitate immediate attent [truncated]