CISA flags CVE-2026-13207 in FUXA SCADA/HMI
This is the boring kind of ICS flaw until it quietly hands out the access map before anyone logs in.
TL;DR
CISA published ICSA-26-181-02 for CVE-2026-13207, a high-severity authentication bypass in Frangoteam FUXA SCADA/HMI 1.3.1 and earlier. Unauthenticated remote attackers can use dot-segment paths in the REST API to enumerate user accounts and role assignments. Critical manufacturing, energy, water operators, and contractors running FUXA should move to 1.3.2 or later. CISA says it has no reports of public exploitation targeting this vulnerability.
For anyone running Frangoteam FUXA SCADA/HMI in an operational technology environment, this is a patch-now advisory, not a governance-calendar item. CISA says CVE-2026-13207 lets unauthenticated remote attackers bypass REST API authentication checks by using dot-segment paths such as /api/./users or /api/project/../users, exposing user and role data on FUXA 1.3.1 and earlier.
The immediate fix is Frangoteam FUXA 1.3.2 or later. CISA also repeats the usual ICS hygiene: keep control systems off the public internet, put them behind firewalls, isolate them from business networks, and update VPNs where remote access is necessary. That advice is generic, but the failure here is not. If a SCADA/HMI instance can disclose its account and role model before authentication, the attacker has been handed a target list for the next step.
CISA reported no known public exploitation targeting CVE-2026-13207 as of the June 30 initial advisory. That is useful, but it is not a reason to wait. The open operational question is whether 1.3.2 fits cleanly into existing FUXA deployments. Until that is tested, asset owners are balancing a normal change-control problem against a network-accessible flaw that exposes access-control metadata without credentials.
Published ·Deep Fathom