CVE-2026-12897: Horner Automation Cscape

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code.

Affected products

Published 2026-06-25. Last modified 2026-06-25.