CVE-2026-8604: ScadaBR

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.

Affected products

Published 2026-05-19. Last modified 2026-07-23.