CVE-2026-25895
published 2026-02-09CVE-2026-25895: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to…
PriorityP188critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
6.34%
93.4th percentile
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| frangoteam | fuxa | < 1.2.10 | 1.2.10 |
Detection & IOCsextracted from sources · hover to see the quote
- ·The vulnerability affects FUXA through version 1.2.9; version 1.2.10 contains the patch. Verify the deployed version via GET /api/version before assuming patched status. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.5CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa9.8CRITICAL
osv9.8CRITICAL
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
ghsa·2026-02-05·CVSS 9.8
CVE-2026-25895 [CRITICAL] CWE-22 FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
### Summary
**Description**
A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
### Impact
This affects all deployments, including those with `runtime.settings.secureEnabled` set to `true`.
Exploitation allows an unauthenticated, remote attacker to overwrite application and system files. If the attacker can overwrite application code, startup scripts, or configuration files that are later executed/loaded, RCE is likely. Depending on deployment configuration and permissions, this may lead to full system compromise
OSV
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
osv·2026-02-05·CVSS 9.8
CVE-2026-25895 [CRITICAL] FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
### Summary
**Description**
A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
### Impact
This affects all deployments, including those with `runtime.settings.secureEnabled` set to `true`.
Exploitation allows an unauthenticated, remote attacker to overwrite application and system files. If the attacker can overwrite application code, startup scripts, or configuration files that are later executed/loaded, RCE is likely. Depending on deployment configuration and permissions, this may lead to full system compromise
VulnCheck
frangoteam fuxa Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2026·CVSS 9.8
CVE-2026-25895 [CRITICAL] frangoteam fuxa Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
frangoteam fuxa Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
Affected: frangoteam fuxa
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://api.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-25895&date=2026-08-18; https://www.linkedin.com/posts/ccondon_kev-vulnerability-rce-share-74954328502136
No detection rules found.
Exploit-DB
FUXA 1.2.9 - RCE
exploitdb·2026-05-21·CVSS 9.5
CVE-2026-25895 [CRITICAL] FUXA 1.2.9 - RCE
FUXA 1.2.9 - RCE
---
# Exploit Title: FUXA 1.2.9 - RCE
# Date: 4/24/2026
# Exploit Author: Anthony Cihan (Hann1bl3L3ct3r)
# Vendor Homepage: https://github.com/frangoteam/FUXA
# Version: Arbitrary File Write -> RCE
Affected: FUXA ` makes
Node's path.resolve() climb out of `appDir` to anywhere the FUXA
process can write.
* `fullPath`/`fileName` strip `..` sequences, so we control the directory
via `destination` and the filename via `file.name`.
Exploitation: pre-auth RCE even when `secureEnabled = true`.
Authorization: this script is for credentialed penetration tests against
systems you are explicitly authorized to assess. Use only inside a defined
engagement scope.
"""
from __future__ import annotations
import argparse
import base64
import json
import posixpath
import secrets
import
Nuclei
FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File Write
nuclei·CVSS 9.8
CVE-2026-25895 [CRITICAL] FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File Write
FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File Write
FUXA, an open-source Node.js SCADA/HMI web interface, through version 1.2.9 exposes an unauthenticated POST /api/upload endpoint that resolves the attacker-controlled `destination` field from the JSON request body against the application directory with only a leading underscore prefix and no containment check. Because path.resolve() honours "../" segments, an unauthenticated attacker can escape the application directory and write arbitrary files anywhere on the filesystem reachable by the service account - for example into the public web root (a/../../client/dist), into cron directories, or over SSH authorized_keys - leading to remote code execution. Version 1.2.10 rejects any destination containing a traversal segment
Hackernews
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
blogs_hackernews·2026-08-24
CVE-2026-19478 ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet.
That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are.
Plenty to clean up. Here’s the short version.
## ⚡ Threat of the Week
U.S. Warns of AI-Powered Attacks on Siemens PLCs — Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series program
Hackernews
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
blogs_hackernews·2026-08-18·CVSS 9.8
CVE-2026-64849 [CRITICAL] Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts.
According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -
CVE-2026-64849 (CVSS score: 9.3) - An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in MLflow that can allow an attacker who can reach the Trac
Wiz
CVE-2026-25895 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.5
CVE-2026-25895 [CRITICAL] CVE-2026-25895 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25895 :
JavaScript vulnerability analysis and mitigation
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
Source : NVD
## 9.5
Score
Published February 9, 2026
Severity CRITICAL
CNA Score 9.5
Affected Technologies
JavaScript
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
fuxa-server
Sources
NVD
npm Severity CRITICAL Has Fix Add
2026-02-09
Published
Exploited in the wild