CVE-2026-22553: Insat Masterscada

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.

Affected products

  • Insat Masterscada: any version

Published 2026-02-24. Last modified 2026-06-17.