Frangoteam FUXA SCADA/HMI

2026-06-30T19:23:29Z648a6b1565e86ce8c86f85f6e996b33cf3652168e846309caeea8892ba00426e
7-zipCISA-ICSA-26-181Delta-ElectronicsFrangoteamICSMitsubishi-Electric","B&ROTPLCRTUSCADASchneider-ElectricStoneFlyStorageauthentication-bypasscommand-injectionhard-coded-credentialsheap-overflowinsufficiently-protected-credentialsmissing-authenticationmodbus-tcppatch-availablerace-conditionsql-injectionxssxxe

What happened

CISA ICSA-26-181 is a consolidated ICS/OT advisory covering multiple vendors and high-impact vulnerabilities affecting SCADA/HMI, PLCs, RTUs, storage concentrators, and data-center monitoring software. Notable issues include an authentication-bypass via dot-segment path normalization in Frangoteam FUXA (CVE-2026-13207) that exposes user/role data; exposed or insufficiently protected credentials in Schneider EasyLogic T150 / Saitel DP (CVE-2026-9650, CVE-2026-9651); multiple critical remote command execution, SQLi, XSS, and hard-coded credential flaws in StoneFly Storage Concentrator (CVE-2026-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ics_advisories
Record identifier
648a6b1565e86ce8c86f85f6e996b33cf3652168e846309caeea8892ba00426e
Enrichment time
2026-06-30T19:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.