Critical SQL Injection Vulnerability (CVE-2026-16462) Discovered in Weidmueller PROCON-WEB SCADA
A critical SQL injection vulnerability, identified as CVE-2026-16462 with a CVSS score of 9.8, has been found in Weidmueller Interface PROCON-WEB SCADA software. This flaw allows a remote, unauthenticated attacker to execute arbitrary SQL commands on affected systems through the unauthenticated GetGridData endpoint. The vulnerability impacts version 1.0.0 of the software, and users are urged to consult the vendor advisory for mitigation steps.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai