CVE-2026-43946: Frangoteam Fuxa
High severity, CVSS 7.7. EPSS: 0.6% chance of exploitation in the next 30 days.
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 patches the issue.
Affected products
- Frangoteam Fuxa: version 1.3.0 only
Published 2026-07-21. Last modified 2026-07-23.