OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-18782

CRITICAL · CVSS 9.8 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Trex Digital Smart Manufacturing Systems Inc.'s Trex MES is vulnerable to SQL injection, allowing attackers to execute arbitrary commands via crafted SQL queries. This critical vulnerability, with a CVSS score of 9.8, poses a significant risk of unauthorized access and manipulation of the system. Organizations using Trex MES should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-18782
Severity
CRITICAL
CVSS
9.8
EPSS
0.48%

Original NVD Description

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.