Vendor
Advantech vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 30 vulnerabilities in Advantech: 0 in the last 7 days and 26 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-73177, was published on 16 September 2026. 17 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 26
- Critical, all time
- 3
- Exploited in the wild
- 0
About Advantech
A global manufacturer of industrial computing, automation, and embedded systems.
Advantech technologies
- Advantech EKI-1242EIMS13
- Advantech EKI-1242IEIMS12
- Advantech ADAM-3600 EdgeLink5
- Advantech EdgeLink4
- Advantech WISE-6610-CB3
- Advantech WISE-6610-EB3
- Advantech WISE-6610-EL-CB3
- Advantech WISE-6610-EL-EB3
- Advantech WISE-6610-EL-JB3
- Advantech WISE-6610-EL-NB3
- Advantech WISE-6610-EL-TB3
- Advantech WISE-6610-JB3
- Advantech WISE-6610-NB3
- Advantech WISE-6610-TB3
- Advantech WISE-6610P-DEA3
- Advantech WISE-6610P-DNA3
- Advantech WISE-6610P-DTA3
Latest Advantech vulnerabilities
- CVE-2026-73177: Advantech EKI-1242EIMS firmware signature verification bypassinfoCVSS 8.6EPSS 0.1%
- CVE-2026-73176: Advantech EKI-1242IEIMS OS command injection in web management interfaceinfoCVSS 8.6EPSS 1.2%
- CVE-2026-73175: Advantech EKI-1242 denial of service in OPC UA gatewayinfoCVSS 7.1EPSS 0.3%
- CVE-2026-73174: Advantech EKI-1242 cleartext transmission of sensitive informationinfoCVSS 8.7EPSS 0.2%
- CVE-2026-73173: Advantech EKI-1242IEIMS missing authentication in management protocolinfoCVSS 8.8EPSS 0.7%
- CVE-2026-73172: Advantech EKI-1242EIMS OS command injection in edgserver managementinfoCVSS 9.3EPSS 2.2%
- CVE-2026-73171: Advantech EKI-1242IEIMS arbitrary file overwrite in backup-restoreinfoCVSS 8.6EPSS 0.5%
- CVE-2026-73170: Advantech EKI-1242EIMS code injection in Modbus CSV importinfoCVSS 8.6EPSS 0.5%
- CVE-2026-73169: Advantech EKI-1242EIMS stored cross-site scripting in Modbus interfaceinfoCVSS 6.3EPSS 0.5%
- CVE-2026-73167: Advantech EKI-1242IEIMS OS command injection in web management interfaceinfoCVSS 8.6EPSS 1.2%
- CVE-2026-73166: Advantech EKI-1242IEIMS code injection in web management interfaceinfoCVSS 8.6EPSS 0.7%
- CVE-2026-73165: Advantech EKI-1242IEIMS OS command injection in web managementinfoCVSS 8.6EPSS 1.2%
- CVE-2026-73164: Advantech EKI-1242IEIMS OS command injection in web managementinfoCVSS 8.6EPSS 1.2%
- CVE-2026-73163: Advantech EKI-1242IEIMS OS command injection in web management interfaceinfoCVSS 8.6EPSS 1.2%
- CVE-2026-19535: Advantech EKI-1242 CSRF in LuCI administrative interfaceinfoCVSS 8.6EPSS 0.3%
- CVE-2026-79698: Advantech WISE-6610 command injection in Node-RED LibrarycriticalCVSS 9.9EPSS 3.1%
- CVE-2026-79697: Advantech WISE-6610 command injection in certificate deletioncriticalCVSS 9.9EPSS 4.9%
- CVE-2026-43833: Advantech ADAM-3600 EdgeLink stack overflow in upload functionalityinfoCVSS 7.5
- CVE-2026-43832: Advantech ADAM-3600 EdgeLink stack overflow in Cookie parsinginfoCVSS 9.2
- CVE-2026-43831: Advantech ADAM-3600 EdgeLink stack overflow in log message functionalityinfoCVSS 9.2
- CVE-2026-43830: Advantech ADAM-3600 EdgeLink command injection in firmware upgradeinfoCVSS 8.6
- CVE-2026-43829: Advantech ADAM-3600 EdgeLink stack buffer overflow in password functionalityinfoCVSS 9.2
- CVE-2026-6890: Advantech ECU-1251D use of default credentials in SSH root accountinfoCVSS 7.1
- CVE-2026-6889: Advantech ECU-1251D denial of service in DNP3DaemoninfoCVSS 6.9
- CVE-2026-14162: Advantech Hospital Queuing Management missing authentication in APIcriticalCVSS 9.8
Most severe Advantech vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-79697: Advantech WISE-6610 command injection in certificate deletioncriticalCVSS 9.9EPSS 4.9%
- CVE-2026-79698: Advantech WISE-6610 command injection in Node-RED LibrarycriticalCVSS 9.9EPSS 3.1%
- CVE-2026-14162: Advantech Hospital Queuing Management missing authentication in APIcriticalCVSS 9.8
- CVE-2026-14161: Advantech Hospital Queuing Management sensitive data exposure in API documentationhighCVSS 7.5
- CVE-2026-2670: Advantech WISE-6610 OS command injection in OpenVPN managementhighCVSS 7.2EPSS 3.6%
- CVE-2026-6888: Advantech multiple IoT and SCADA products SQL injectionhighCVSS 7.2
- CVE-2026-36226: Advantech WebAccess/SCADA XSS in Create New Project UsermediumCVSS 6.1EPSS 0.3%
- CVE-2025-34257: Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the…mediumCVSS 5.4EPSS 0.3%
- CVE-2026-73172: Advantech EKI-1242EIMS OS command injection in edgserver managementinfoCVSS 9.3EPSS 2.2%
- CVE-2026-43832: Advantech ADAM-3600 EdgeLink stack overflow in Cookie parsinginfoCVSS 9.2
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 1 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 7 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 2 | 2 | |
| 14 Sep 2026 | 15 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/advantech.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Advantech vulnerabilities", https://junglewise.ai/threats/vendors/advantech, 26 September 2026.