All-Line Equipment Company Fuel-Boss
2026-08-31T19:23:19Z•316657c45c0f5d15253ea7c0833395136aa22542c92795106a7fe176606cfd76
CVE-2018-1285CVE-2018-19518CVE-2019-11043CVE-2025-2399CVE-2025-3511CVE-2026-18717CVE-2026-69658CVE-2026-71187CVE-2026-73125CVE-2026-73809CVE-2026-73819CVE-2026-75112CVE-2026-75548CVE-2026-75814CVE-2026-76133CVE-2026-76179CVE-2026-76940CVE-2026-76943CVE-2026-77966CVE-2026-77975CVE-2026-77977CVE-2026-78037CVE-2026-78239All-Line Equipment CompanyApplied Systems EngineeringCISA ICS advisoryEbyteMitsubishi ElectricOS command injectionOT securityRockwell AutomationXXEXiiaozetarbitrary file readarbitrary file writeargument injectionauthentication bypassbuffer overflowdenial of serviceimproper certificate validationindustrial control systemsmissing authenticationremote code executionweak password hashing
What happened
CISA ICS advisories dated August 27, 2026 describe vulnerabilities affecting industrial control systems, communications test equipment, fleet-management software, embedded devices, and Mitsubishi Electric automation products. The issues include unauthenticated access, authentication bypass, OS command injection, arbitrary file read/write, XXE, improper certificate validation, weak password hashing, buffer overflow, argument injection, and denial-of-service conditions. Several advisories carry critical CVSS scores of 9.8 and could enable complete device compromise or remote code execution.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ics_advisories
- Record identifier
- 316657c45c0f5d15253ea7c0833395136aa22542c92795106a7fe176606cfd76
- Enrichment time
- 2026-08-31T19:23:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.