Technology · MB connect line
MB connect line mymbCONNECT24 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 42 vulnerabilities in MB connect line mymbCONNECT24: 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-14448, was published on 20 July 2026.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 0
- Exploited in the wild
- 0
About MB connect line mymbCONNECT24
A private cloud version of the mbCONNECT24 remote service platform for machine communication.
Latest MB connect line mymbCONNECT24 vulnerabilities
- CVE-2026-14448: MB connect line and Helmholz OS command injection in system_certificates viewhighCVSS 7.2
- CVE-2026-10521: MB connect line mbCONNECT24 forced browsing in configuration settingshighCVSS 7.2
- CVE-2026-40850: MB connect line mbCONNECT24 SQL injection in getAccountDatahighCVSS 7.5
- CVE-2026-40849: MB connect line mbCONNECT24 SQL injection in user_alarmprofile viewmediumCVSS 6.5
- CVE-2026-40848: MB connect line mbCONNECT24 SQL injection in tag viewmediumCVSS 6.5
- CVE-2026-40847: MB connect line mbCONNECT24 SQL injection in system_tag viewmediumCVSS 6.5
- CVE-2026-40846: MB connect line mbCONNECT24 SQL injection in system viewmediumCVSS 6.5
- CVE-2026-40845: MB connect line mbCONNECT24 SQL injection in devices_configuration viewmediumCVSS 6.5
- CVE-2026-40844: MB connect line mbCONNECT24 SQL injection in dashboard viewmediumCVSS 6.5
- CVE-2026-40843: MB connect line mbCONNECT24 SQL injection in alarming viewmediumCVSS 6.5
- CVE-2026-40842: MB connect line mbCONNECT24 SQL injection in getWidgetTagsmediumCVSS 6.5
- CVE-2026-40841: MB connect line mbCONNECT24 SQL injection in getProjectTagsmediumCVSS 6.5
- CVE-2026-40840: MB connect line mbCONNECT24 SQL injection in VerifyCreateLicencesmediumCVSS 6.5
- CVE-2026-40839: MB connect line mbCONNECT24 SQL injection in getComponentScalingsmediumCVSS 6.5
- CVE-2026-40838: MB connect line mbCONNECT24 SQL injection in getDeviceScalingsmediumCVSS 6.5
- CVE-2026-40837: MB connect line mbCONNECT24 SQL injection in getProjectScalingsmediumCVSS 6.5
- CVE-2026-40836: MB connect line mbCONNECT24 SQL injection in inmessage modelhighCVSS 7.1
- CVE-2026-40835: MB connect line mbCONNECT24 SQL injection in saveObjectFromDatamediumCVSS 6.5
- CVE-2026-40834: MB connect line mbCONNECT24 SQL injection in saveDashboardLayouthighCVSS 7.1
- CVE-2026-40833: MB connect line mbCONNECT24 SQL injection in dash.phphighCVSS 7.1
- CVE-2026-40832: MB connect line mbCONNECT24 SQL injection in getDevicegroupsmediumCVSS 6.5
- CVE-2026-40831: MB connect line mbCONNECT24 SQL injection in Easy ViewmediumCVSS 6.5
- CVE-2026-40830: MB connect line mbCONNECT24 SQL injection in admin.mbnetj.phpmediumCVSS 5.5
- CVE-2026-40829: MB connect line mbCONNECT24 SQL injection in UpdateParammediumCVSS 5.5
- CVE-2026-40828: MB connect line mbCONNECT24 SQL injection in DeleteSysLogEntrymediumCVSS 5.5
Most severe MB connect line mymbCONNECT24 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-40850: MB connect line mbCONNECT24 SQL injection in getAccountDatahighCVSS 7.5
- CVE-2026-40819: MB connect line mbCONNECT24 SQL injection in sync_data24 taskhighCVSS 7.5
- CVE-2026-40818: MB connect line mbCONNECT24 SQL injection in _mb24confi_getDevicehighCVSS 7.5
- CVE-2026-40817: MB connect line mbCONNECT24 SQL injection in getAlarmProfileshighCVSS 7.5
- CVE-2026-40816: MB connect line mbCONNECT24 SQL injection in mb24alarm.phphighCVSS 7.5
- CVE-2026-40815: MB connect line mbCONNECT24 SQL injection in _mb24api_getUserAccounthighCVSS 7.5
- CVE-2026-40814: MB connect line mbCONNECT24 SQL injection in dataapi.phphighCVSS 7.5
- CVE-2026-40813: MB connect line mbCONNECT24 SQL injection in getLiveValueshighCVSS 7.5
- CVE-2026-40812: MB connect line mbCONNECT24 SQL injection in getLiveValueshighCVSS 7.5
- CVE-2026-40811: MB connect line mbCONNECT24 SQL injection in ssoabstractservicehighCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/mymbconnect24.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "MB connect line mymbCONNECT24 vulnerabilities", https://junglewise.ai/threats/technologies/mymbconnect24, 26 September 2026.