LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-6284 - Vulnerability Analysis

CriticalCVSS: 9.1

Last Updated: April 20, 2026

PLC - Authentication Bypass

Published: April 17, 2026Updated: April 20, 2026Remote Exploitable

Overview

A PLC contains a broken authentication vulnerability caused by limited password complexity and lack of input limiters, letting attackers with network access brute force passwords to gain unauthorized access.

Severity & Score

Severity: Critical
CVSS Score: 9.1
EPSS Score: 1.1%(Probability of exploitation in next 30 days)

Impact

Attackers can gain unauthorized access to systems and services by brute forcing passwords.

Mitigation

Implement stronger password complexity and input limiters or update to the latest secure version.

Social Media Activity(1 post)

ThreatNoir
ThreatNoir
@threatnoir
Apr 18, 2026

⚠️ CRITICAL: Horner Automation Cscape and XL4, XL7 PLC Horner Automation Cscape v10.0, XL4 PLC v16.32.0, and XL7 PLC v15.60 contain a critical password brute-force vulnerability (CVE-2026-6284, CVSS 9.1) with no rate limiting. This affects manufacturing environments globally and allows unauthenticated network attackers to compromise PLCs controlling cr… https://threatnoir.com/focus #infosec #cybersecurity

View original post

Details

CVE ID
CVE-2026-6284
Severity
Critical
CVSS Score
9.1
Type
broken_authentication
Status
unconfirmed
EPSS
1.1%
Social Posts
1

CWE

  • CWE-521

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Score

1.1%Probability of exploitation in the next 30 days