logo

Weidmueller PROCON-WEB SCADA SQL Injection CVE-2026-16462 Rated CVSS 9.8

ID: aa98ad16-b4f0-51a0-9b03-4a0619fcc620

STIX ID: report--aa98ad16-b4f0-51a0-9b03-4a0619fcc620

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: Do Son

...
...

A critical unauthenticated SQL injection (CVE-2026-16462, CVSS 9.8) affects Weidmueller PROCON-WEB SCADA (versions up to 6.11.2 back to 1.0.0) via the GetGridData endpoint, enabling remote attackers to execute arbitrary SQL; vendor patch (6.11.3) is available, no confirmed exploitation has been reported and EPSS is low (0.4%).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.