CVE-2026-19657: Scada-LTS

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.

Affected products

Published 2026-08-12. Last modified 2026-08-25.