CVE-2026-43946: Frangoteam Fuxa

High severity, CVSS 7.7. EPSS: 0.6% chance of exploitation in the next 30 days.

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 patches the issue.

Affected products

Published 2026-07-21. Last modified 2026-07-23.