CVE-2026-19657: Scada-LTS
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.
Affected products
- Scada-LTS Scada-LTS: version 2.7.8.1 only
Published 2026-08-12. Last modified 2026-08-25.