Critical Airleader Vulnerability Exposes Systems to Exploitable Remote Attacks
ID: 5fa563ec-4c7a-5977-999f-3f40326add05
STIX ID: report--5fa563ec-4c7a-5977-999f-3f40326add05
Feed Name: GBHackers
**Critical CVE-2026-1358 (CVSS 9.8)**: an unrestricted file upload flaw in Airleader Master (≤6.381) permits remote code execution and potential full control of industrial control systems across chemical, manufacturing, energy, food, healthcare, transportation, and water sectors; CISA published an advisory after disclosure by researcher Angel Lomeli (SySS GmbH) and recommends isolating ICS from the internet, network segmentation, updated VPNs, and defense-in-depth measures—no active exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
