CVE-2026-12897: Horner Automation Cscape
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code.
Affected products
- Horner Automation Cscape: before 10.2 SP3 (fixed in 10.2 SP3)
Published 2026-06-25. Last modified 2026-06-25.