logo

Critical Airleader Vulnerability Exposes Systems to Exploitable Remote Attacks

ID: 5fa563ec-4c7a-5977-999f-3f40326add05

STIX ID: report--5fa563ec-4c7a-5977-999f-3f40326add05

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

Author: Divya

...
...

**Critical CVE-2026-1358 (CVSS 9.8)**: an unrestricted file upload flaw in Airleader Master (≤6.381) permits remote code execution and potential full control of industrial control systems across chemical, manufacturing, energy, food, healthcare, transportation, and water sectors; CISA published an advisory after disclosure by researcher Angel Lomeli (SySS GmbH) and recommends isolating ICS from the internet, network segmentation, updated VPNs, and defense-in-depth measures—no active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.