A critical vulnerability tracked as CVE-2026-25895 affects FUXA versions <= 1.2.9, allowing an unauthenticated attacker to exploit a path traversal flaw and gain an arbitrary file-write primitive. Public reporting and a related detection template describe the issue as impacting the FUXA SCADA/OT management dashboard, where successful exploitation can let a remote attacker overwrite files without authentication.
VulnCheck reported active malicious scanning for exposed FUXA systems, observing a single IP broadly probing internet-facing instances and attempting to overwrite main.js with junk data. Researchers said the same file-write capability was sufficient in testing to drop a root shell, underscoring the risk of full compromise on vulnerable OT deployments; VulnCheck also estimated roughly 60 FUXA instances were publicly exposed and noted prior exploitation involving other FUXA vulnerabilities, including CVE-2026-25939 and CVE-2023-33831.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
A GitHub pull request documented CVE-2026-25895 as affecting FUXA versions up to and including 1.2.9 and described it as an unauthenticated path traversal leading to arbitrary file write. On August 18, 2026, the PR workflow showed self-assignment, automated labeling, reviewer request, and assignment activity.
VulnCheck made an exploit, PCAP, Suricata rules, Snort rules, and a target Docker container for CVE-2026-25895 available to Initial Access Intelligence customers on July 25, 2026. The materials supported detection and testing of the FUXA path traversal issue.
On July 25, 2026, VulnCheck's Canary network observed malicious scanning from a single IP for vulnerable FUXA instances exploiting CVE-2026-25895. The requests attempted to overwrite main.js with junk data via the path traversal file-write primitive, though VulnCheck had not yet seen RCE payloads dropped in this activity.
VulnCheck reported that exploitation activity targeting FUXA vulnerability CVE-2023-33831 dates back to November 2025. The flaw was described as a remote command execution vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcelinkedin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.