Vendor
MB connect line vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 41 vulnerabilities in MB connect line: 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-14448, was published on 20 July 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 0
- Exploited in the wild
- 0
About MB connect line
MB connect line is a provider of solutions for remote maintenance and secure communication in industrial automation.
MB connect line technologies
Latest MB connect line vulnerabilities
- CVE-2026-14448: MB connect line and Helmholz OS command injection in system_certificates viewhighCVSS 7.2
- CVE-2026-10521: MB connect line mbCONNECT24 forced browsing in configuration settingshighCVSS 7.2
- CVE-2026-40852: MB connect line mbNET OS command injection in config generatorhighCVSS 7.2
- CVE-2026-40851: MB connect line mbNET code execution in cfgparser via USBhighCVSS 8.4
- CVE-2026-40849: MB connect line mbCONNECT24 SQL injection in user_alarmprofile viewmediumCVSS 6.5
- CVE-2026-40848: MB connect line mbCONNECT24 SQL injection in tag viewmediumCVSS 6.5
- CVE-2026-40847: MB connect line mbCONNECT24 SQL injection in system_tag viewmediumCVSS 6.5
- CVE-2026-40846: MB connect line mbCONNECT24 SQL injection in system viewmediumCVSS 6.5
- CVE-2026-40844: MB connect line mbCONNECT24 SQL injection in dashboard viewmediumCVSS 6.5
- CVE-2026-40843: MB connect line mbCONNECT24 SQL injection in alarming viewmediumCVSS 6.5
- CVE-2026-40842: MB connect line mbCONNECT24 SQL injection in getWidgetTagsmediumCVSS 6.5
- CVE-2026-40841: MB connect line mbCONNECT24 SQL injection in getProjectTagsmediumCVSS 6.5
- CVE-2026-40840: MB connect line mbCONNECT24 SQL injection in VerifyCreateLicencesmediumCVSS 6.5
- CVE-2026-40839: MB connect line mbCONNECT24 SQL injection in getComponentScalingsmediumCVSS 6.5
- CVE-2026-40838: MB connect line mbCONNECT24 SQL injection in getDeviceScalingsmediumCVSS 6.5
- CVE-2026-40837: MB connect line mbCONNECT24 SQL injection in getProjectScalingsmediumCVSS 6.5
- CVE-2026-40836: MB connect line mbCONNECT24 SQL injection in inmessage modelhighCVSS 7.1
- CVE-2026-40834: MB connect line mbCONNECT24 SQL injection in saveDashboardLayouthighCVSS 7.1
- CVE-2026-40833: MB connect line mbCONNECT24 SQL injection in dash.phphighCVSS 7.1
- CVE-2026-40832: MB connect line mbCONNECT24 SQL injection in getDevicegroupsmediumCVSS 6.5
- CVE-2026-40831: MB connect line mbCONNECT24 SQL injection in Easy ViewmediumCVSS 6.5
- CVE-2026-40830: MB connect line mbCONNECT24 SQL injection in admin.mbnetj.phpmediumCVSS 5.5
- CVE-2026-40829: MB connect line mbCONNECT24 SQL injection in UpdateParammediumCVSS 5.5
- CVE-2026-40828: MB connect line mbCONNECT24 SQL injection in DeleteSysLogEntrymediumCVSS 5.5
- CVE-2026-40827: MB connect line mbCONNECT24 SQL injection in _RemoveRequestmediumCVSS 5.5
Most severe MB connect line vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-40851: MB connect line mbNET code execution in cfgparser via USBhighCVSS 8.4
- CVE-2026-40819: MB connect line mbCONNECT24 SQL injection in sync_data24 taskhighCVSS 7.5
- CVE-2026-40818: MB connect line mbCONNECT24 SQL injection in _mb24confi_getDevicehighCVSS 7.5
- CVE-2026-40817: MB connect line mbCONNECT24 SQL injection in getAlarmProfileshighCVSS 7.5
- CVE-2026-40816: MB connect line mbCONNECT24 SQL injection in mb24alarm.phphighCVSS 7.5
- CVE-2026-40815: MB connect line mbCONNECT24 SQL injection in _mb24api_getUserAccounthighCVSS 7.5
- CVE-2026-40814: MB connect line mbCONNECT24 SQL injection in dataapi.phphighCVSS 7.5
- CVE-2026-40813: MB connect line mbCONNECT24 SQL injection in getLiveValueshighCVSS 7.5
- CVE-2026-40812: MB connect line mbCONNECT24 SQL injection in getLiveValueshighCVSS 7.5
- CVE-2026-40811: MB connect line mbCONNECT24 SQL injection in ssoabstractservicehighCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/mb-connect-line.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "MB connect line vulnerabilities", https://junglewise.ai/threats/vendors/mb-connect-line, 26 September 2026.