TL;DR
CISA published ICS advisory ICSA-26-204-04 on July 23, 2026. It details five security bugs in Panduit IntraVUE, an industrial network monitoring platform built by Pronetiqs. The most severe Panduit IntraVUE vulnerability, CVE-2026-42933, earns a maximum CVSS score of 10.
- Total: 5 CVEs
- Severity: 2 Critical · 2 High · 1 Medium
- Actively exploited: None confirmed
- Highest severity: 10.0 (Critical · CVSSv3) — CVE-2026-42933
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-42933 | 10 | Unintended Proxy or Intermediary in by | — | Not exploited |
| CVE-2026-28698 | 8.6 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in by | — | Not exploited |
| CVE-2026-40430 | 7.5 | Plaintext Storage of a Password in by | — | Not exploited |
| CVE-2026-50044 | 6.8 | Inadequate Encryption Strength in by | — | Not exploited |
| CVE-2026-44955 | 5.3 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in by | — | Not exploited |
Why It Matters
IntraVUE maps and monitors devices across factory networks. Because of that role, the software often bridges the IT and OT sides of a plant. An attacker sitting on the corporate network could therefore reach industrial control devices directly. No physical access is required, and no insider knowledge or special tooling either. For many manufacturers, this collapses the segmentation boundary they rely on.
How the Attack Works
CVE-2026-42933 is a confused deputy issue, classified as CWE-441. IntraVUE can act as an active proxy, so requests pass through it and land inside protected OT segments.
Four supporting flaws widen the blast radius. CVE-2026-40430 stores a password in plaintext and can leak cleartext credentials through the API, at CVSS 8.7. CVE-2026-28698 exposes the underlying host or share filesystem, scoring 9.2 under CVSS 4.0. CVE-2026-50044 relies on a weak hash, which opens the door to pass-the-hash attacks. Finally, CVE-2026-44955 lets unauthenticated users enumerate assets.
Chained together, these gaps turn a monitoring tool into a pivot point. Researcher Phlebas of Lumintel reported the set to CISA. No exploitation in the wild has been confirmed, and no public proof-of-concept exists.
Affected Versions
All Panduit IntraVUE builds up to and including 3.2.1a14 are affected.
Patch and Mitigation Steps
Pronetiqs advises users to update to IntraVUE 3.2.1a16 or later. Patch first, then review exposure. Keep the server off the public internet, and place it behind a firewall. Segment it away from business networks wherever possible. Rotate any admin credentials that the plaintext storage flaw may have leaked.
Further defensive guidance appears in CISA advisory ICSA-26-204-04, and Pronetiqs answers direct questions at info@pronetiqs.com. Given the CVSS 10 rating, treat this Panduit IntraVUE vulnerability as an urgent upgrade.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.