{"schema_version":1,"title":"Frangoteam FUXA vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 32 vulnerabilities in Frangoteam FUXA: 0 in the last 7 days and 12 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-67443, was published on 18 August 2026.","url":"https://junglewise.ai/threats/technologies/fuxa","json_url":"https://junglewise.ai/threats/technologies/fuxa.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/fuxa","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":9,"all_time":32,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":12,"last_365_days":28},"latest":[{"cve":"CVE-2026-67443","cvss":8.6,"epss":0.0069,"slug":"cve-2026-67443-fuxa-node-red-authorization-bypass","title":"FUXA Node-RED authorization bypass","severity":"info","exploited":false,"published_at":"2026-08-18T20:17:22.963+00:00","url":"https://junglewise.ai/threats/cve-2026-67443-fuxa-node-red-authorization-bypass"},{"cve":"CVE-2026-67440","epss":0.0054,"slug":"cve-2026-67440-fuxa-unauthenticated-information-disclosure-in-socket-io-handlers","title":"FUXA unauthenticated information disclosure in Socket.IO handlers","severity":"info","exploited":false,"published_at":"2026-08-18T20:17:22.81+00:00","url":"https://junglewise.ai/threats/cve-2026-67440-fuxa-unauthenticated-information-disclosure-in-socket-io-handlers"},{"cve":"CVE-2026-65985","epss":0.0047,"slug":"cve-2026-65985-fuxa-ssrf-vulnerability-in-device-webapi-request-socket-io","title":"FUXA SSRF vulnerability in device-webapi-request Socket.IO handler","severity":"info","exploited":false,"published_at":"2026-08-18T20:17:20.74+00:00","url":"https://junglewise.ai/threats/cve-2026-65985-fuxa-ssrf-vulnerability-in-device-webapi-request-socket-io"},{"cve":"CVE-2026-65984","cvss":7.5,"epss":0.0052,"slug":"cve-2026-65984-fuxa-session-fixation-via-stale-jwt-refresh","title":"FUXA session fixation via stale JWT refresh","severity":"info","exploited":false,"published_at":"2026-08-18T20:17:20.557+00:00","url":"https://junglewise.ai/threats/cve-2026-65984-fuxa-session-fixation-via-stale-jwt-refresh"},{"cve":"CVE-2026-47721","cvss":6.3,"epss":0.0043,"slug":"cve-2026-47721-frangoteam-fuxa-privilege-escalation-in-scheduler-api","title":"FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in s","severity":"medium","exploited":false,"published_at":"2026-08-18T20:17:15.383+00:00","url":"https://junglewise.ai/threats/cve-2026-47721-frangoteam-fuxa-privilege-escalation-in-scheduler-api"},{"cve":"CVE-2026-47720","cvss":5.3,"epss":0.0064,"slug":"cve-2026-47720-frangoteam-fuxa-sql-injection-in-tdengine-daq-connector","title":"FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdStrin","severity":"medium","exploited":false,"published_at":"2026-08-18T20:17:15.25+00:00","url":"https://junglewise.ai/threats/cve-2026-47720-frangoteam-fuxa-sql-injection-in-tdengine-daq-connector"},{"cve":"CVE-2026-47719","cvss":8.2,"epss":0.0059,"slug":"cve-2026-47719-frangoteam-fuxa-unauthenticated-ssrf-in-socket-io-handlers","title":"FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Sock","severity":"high","exploited":false,"published_at":"2026-08-18T20:17:15.103+00:00","url":"https://junglewise.ai/threats/cve-2026-47719-frangoteam-fuxa-unauthenticated-ssrf-in-socket-io-handlers"},{"cve":"CVE-2026-72586","cvss":7.5,"epss":0.0063,"slug":"cve-2026-72586-frangoteam-fuxa-missing-authentication-in-daq-query-handler","title":"frangoteam FUXA missing authentication in DAQ_QUERY handler","severity":"high","exploited":false,"published_at":"2026-08-10T11:17:31.637+00:00","url":"https://junglewise.ai/threats/cve-2026-72586-frangoteam-fuxa-missing-authentication-in-daq-query-handler"},{"cve":"CVE-2026-43947","cvss":4,"epss":0.0091,"slug":"cve-2026-43947-frangoteam-fuxa-unauthenticated-rce-in-api-runscript","title":"frangoteam FUXA unauthenticated RCE in /api/runscript","severity":"high","exploited":false,"published_at":"2026-07-21T22:17:01.56+00:00","url":"https://junglewise.ai/threats/cve-2026-43947-frangoteam-fuxa-unauthenticated-rce-in-api-runscript"},{"cve":"CVE-2026-43946","cvss":4,"epss":0.0057,"slug":"cve-2026-43946-frangoteam-fuxa-authorization-bypass-in-api-gettagvalue","title":"frangoteam FUXA authorization bypass in /api/getTagValue","severity":"high","exploited":false,"published_at":"2026-07-21T22:17:01.41+00:00","url":"https://junglewise.ai/threats/cve-2026-43946-frangoteam-fuxa-authorization-bypass-in-api-gettagvalue"},{"cve":"CVE-2026-43945","cvss":4,"epss":0.0084,"slug":"cve-2026-43945-frangoteam-fuxa-authentication-bypass-and-rce-via-path","title":"frangoteam FUXA authentication bypass and RCE via path manipulation","severity":"high","exploited":false,"published_at":"2026-07-21T22:17:01.25+00:00","url":"https://junglewise.ai/threats/cve-2026-43945-frangoteam-fuxa-authentication-bypass-and-rce-via-path"},{"cve":"CVE-2026-13207","cvss":7.5,"slug":"cve-2026-13207-frangoteam-fuxa-authentication-bypass-in-rest-api","title":"Frangoteam FUXA authentication bypass in REST API","severity":"high","exploited":false,"published_at":"2026-06-30T21:16:30.5+00:00","url":"https://junglewise.ai/threats/cve-2026-13207-frangoteam-fuxa-authentication-bypass-in-rest-api"},{"cve":"CVE-2026-47718","cvss":4,"epss":0.0046,"slug":"cve-2026-47718-frangoteam-fuxa-authentication-bypass-in-protected-read-apis","title":"frangoteam FUXA authentication bypass in protected read APIs","severity":"medium","exploited":false,"published_at":"2026-05-28T20:33:11+00:00","url":"https://junglewise.ai/threats/cve-2026-47718-frangoteam-fuxa-authentication-bypass-in-protected-read-apis"},{"cve":"CVE-2026-47717","cvss":7.5,"epss":0.0138,"slug":"cve-2026-47717-fuxa-unauthenticated-project-data-disclosure-in-api","title":"FUXA unauthenticated project data disclosure in API","severity":"high","exploited":false,"published_at":"2026-05-27T22:51:18+00:00","url":"https://junglewise.ai/threats/cve-2026-47717-fuxa-unauthenticated-project-data-disclosure-in-api"},{"cve":"CVE-2025-69971","cvss":8.1,"epss":0.0208,"slug":"cve-2025-69971-frangoteam-fuxa-hardcoded-jwt-signing-secret-fallback","title":"frangoteam FUXA hardcoded JWT signing secret fallback","severity":"high","exploited":false,"published_at":"2026-03-07T02:31:18+00:00","url":"https://junglewise.ai/threats/cve-2025-69971-frangoteam-fuxa-hardcoded-jwt-signing-secret-fallback"},{"cve":"CVE-2025-69985","cvss":3.1,"epss":0.0573,"slug":"cve-2025-69985-fuxa-authentication-bypass-in-jwt-middleware-via-referer-header","title":"FUXA authentication bypass in JWT middleware via Referer header spoofing","severity":"low","exploited":false,"published_at":"2026-02-24T18:31:02+00:00","url":"https://junglewise.ai/threats/cve-2025-69985-fuxa-authentication-bypass-in-jwt-middleware-via-referer-header"},{"cve":"CVE-2026-25939","cvss":4,"epss":0.0084,"slug":"cve-2026-25939-fuxa-authorization-bypass-in-scheduler-endpoint","title":"FUXA authorization bypass in scheduler endpoint","severity":"medium","exploited":false,"published_at":"2026-02-10T00:28:28+00:00","url":"https://junglewise.ai/threats/cve-2026-25939-fuxa-authorization-bypass-in-scheduler-endpoint"},{"cve":"CVE-2026-25938","cvss":4,"epss":0.0133,"slug":"cve-2026-25938-fuxa-authentication-bypass-in-node-red-integration","title":"FUXA authentication bypass in Node-RED integration","severity":"medium","exploited":false,"published_at":"2026-02-10T00:27:31+00:00","url":"https://junglewise.ai/threats/cve-2026-25938-fuxa-authentication-bypass-in-node-red-integration"},{"cve":"CVE-2026-25752","cvss":4,"epss":0.0066,"slug":"cve-2026-25752-fuxa-unauthenticated-remote-arbitrary-device-tag-write","title":"FUXA unauthenticated remote arbitrary device tag write","severity":"medium","exploited":false,"published_at":"2026-02-05T00:38:25+00:00","url":"https://junglewise.ai/threats/cve-2026-25752-fuxa-unauthenticated-remote-arbitrary-device-tag-write"},{"cve":"CVE-2026-25895","cvss":4,"epss":0.0621,"slug":"cve-2026-25895-fuxa-path-traversal-arbitrary-file-write-in-upload-api","title":"FUXA path traversal arbitrary file write in upload API","severity":"medium","exploited":false,"published_at":"2026-02-05T00:37:30+00:00","url":"https://junglewise.ai/threats/cve-2026-25895-fuxa-path-traversal-arbitrary-file-write-in-upload-api"},{"cve":"CVE-2026-25894","cvss":4,"epss":0.0124,"slug":"cve-2026-25894-frangoteam-fuxa-remote-code-execution-via-hardcoded-jwt-secret","title":"FUXA unauthenticated remote code execution via hardcoded JWT secret","severity":"medium","exploited":false,"published_at":"2026-02-05T00:36:30+00:00","url":"https://junglewise.ai/threats/cve-2026-25894-frangoteam-fuxa-remote-code-execution-via-hardcoded-jwt-secret"},{"cve":"CVE-2026-25751","cvss":4,"epss":0.0037,"slug":"cve-2026-25751-fuxa-unauthenticated-exposure-of-plaintext-database-credentials","title":"FUXA unauthenticated exposure of plaintext database credentials","severity":"medium","exploited":false,"published_at":"2026-02-05T00:33:44+00:00","url":"https://junglewise.ai/threats/cve-2026-25751-fuxa-unauthenticated-exposure-of-plaintext-database-credentials"},{"cve":"CVE-2026-25893","cvss":4,"epss":0.0108,"slug":"cve-2026-25893-fuxa-authentication-bypass-and-remote-code-execution-via","title":"FUXA authentication bypass and remote code execution via heartbeat refresh API","severity":"medium","exploited":false,"published_at":"2026-02-05T00:27:53+00:00","url":"https://junglewise.ai/threats/cve-2026-25893-fuxa-authentication-bypass-and-remote-code-execution-via"},{"cvss":9.8,"slug":"frangoteam-fuxa-hard-coded-secret-in-jwt-authentication-88d907ce","title":"frangoteam FUXA hard-coded secret in JWT authentication","severity":"high","exploited":false,"published_at":"2026-02-03T18:30:47+00:00","url":"https://junglewise.ai/threats/frangoteam-fuxa-hard-coded-secret-in-jwt-authentication-88d907ce"},{"cve":"CVE-2025-69970","cvss":4,"epss":0.0048,"slug":"cve-2025-69970-fuxa-insecure-default-authentication-configuration","title":"FUXA insecure default authentication configuration","severity":"medium","exploited":false,"published_at":"2026-02-03T18:30:47+00:00","url":"https://junglewise.ai/threats/cve-2025-69970-fuxa-insecure-default-authentication-configuration"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Frangoteam FUXA","slug":"fuxa","vendor":{"name":"Frangoteam","slug":"frangoteam","url":"https://junglewise.ai/threats/vendors/frangoteam"},"aliases":[],"category":"web-server","description":"A web-based HMI/SCADA visualization platform for monitoring and controlling industrial processes.","url":"https://junglewise.ai/threats/technologies/fuxa"},"most_severe":[{"cvss":9.8,"slug":"frangoteam-fuxa-hard-coded-secret-in-jwt-authentication-88d907ce","title":"frangoteam FUXA hard-coded secret in JWT authentication","severity":"high","exploited":false,"published_at":"2026-02-03T18:30:47+00:00","url":"https://junglewise.ai/threats/frangoteam-fuxa-hard-coded-secret-in-jwt-authentication-88d907ce"},{"cve":"CVE-2026-47719","cvss":8.2,"epss":0.0059,"slug":"cve-2026-47719-frangoteam-fuxa-unauthenticated-ssrf-in-socket-io-handlers","title":"FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Sock","severity":"high","exploited":false,"published_at":"2026-08-18T20:17:15.103+00:00","url":"https://junglewise.ai/threats/cve-2026-47719-frangoteam-fuxa-unauthenticated-ssrf-in-socket-io-handlers"},{"cve":"CVE-2025-69971","cvss":8.1,"epss":0.0208,"slug":"cve-2025-69971-frangoteam-fuxa-hardcoded-jwt-signing-secret-fallback","title":"frangoteam FUXA hardcoded JWT signing secret fallback","severity":"high","exploited":false,"published_at":"2026-03-07T02:31:18+00:00","url":"https://junglewise.ai/threats/cve-2025-69971-frangoteam-fuxa-hardcoded-jwt-signing-secret-fallback"},{"cve":"CVE-2026-47717","cvss":7.5,"epss":0.0138,"slug":"cve-2026-47717-fuxa-unauthenticated-project-data-disclosure-in-api","title":"FUXA unauthenticated project data disclosure in API","severity":"high","exploited":false,"published_at":"2026-05-27T22:51:18+00:00","url":"https://junglewise.ai/threats/cve-2026-47717-fuxa-unauthenticated-project-data-disclosure-in-api"},{"cve":"CVE-2026-72586","cvss":7.5,"epss":0.0063,"slug":"cve-2026-72586-frangoteam-fuxa-missing-authentication-in-daq-query-handler","title":"frangoteam FUXA missing authentication in DAQ_QUERY handler","severity":"high","exploited":false,"published_at":"2026-08-10T11:17:31.637+00:00","url":"https://junglewise.ai/threats/cve-2026-72586-frangoteam-fuxa-missing-authentication-in-daq-query-handler"},{"cve":"CVE-2026-13207","cvss":7.5,"slug":"cve-2026-13207-frangoteam-fuxa-authentication-bypass-in-rest-api","title":"Frangoteam FUXA authentication bypass in REST API","severity":"high","exploited":false,"published_at":"2026-06-30T21:16:30.5+00:00","url":"https://junglewise.ai/threats/cve-2026-13207-frangoteam-fuxa-authentication-bypass-in-rest-api"},{"cve":"CVE-2026-43947","cvss":4,"epss":0.0091,"slug":"cve-2026-43947-frangoteam-fuxa-unauthenticated-rce-in-api-runscript","title":"frangoteam FUXA unauthenticated RCE in /api/runscript","severity":"high","exploited":false,"published_at":"2026-07-21T22:17:01.56+00:00","url":"https://junglewise.ai/threats/cve-2026-43947-frangoteam-fuxa-unauthenticated-rce-in-api-runscript"},{"cve":"CVE-2026-43945","cvss":4,"epss":0.0084,"slug":"cve-2026-43945-frangoteam-fuxa-authentication-bypass-and-rce-via-path","title":"frangoteam FUXA authentication bypass and RCE via path manipulation","severity":"high","exploited":false,"published_at":"2026-07-21T22:17:01.25+00:00","url":"https://junglewise.ai/threats/cve-2026-43945-frangoteam-fuxa-authentication-bypass-and-rce-via-path"},{"cve":"CVE-2026-43946","cvss":4,"epss":0.0057,"slug":"cve-2026-43946-frangoteam-fuxa-authorization-bypass-in-api-gettagvalue","title":"frangoteam FUXA authorization bypass in /api/getTagValue","severity":"high","exploited":false,"published_at":"2026-07-21T22:17:01.41+00:00","url":"https://junglewise.ai/threats/cve-2026-43946-frangoteam-fuxa-authorization-bypass-in-api-gettagvalue"},{"cve":"CVE-2026-47721","cvss":6.3,"epss":0.0043,"slug":"cve-2026-47721-frangoteam-fuxa-privilege-escalation-in-scheduler-api","title":"FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in s","severity":"medium","exploited":false,"published_at":"2026-08-18T20:17:15.383+00:00","url":"https://junglewise.ai/threats/cve-2026-47721-frangoteam-fuxa-privilege-escalation-in-scheduler-api"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}