Critical Airleader Vulnerability Exposes Systems to Exploitable Remote Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has disclosed a significant security vulnerability in the Airleader Master software, which could potentially impact industrial control systems across various critical infrastructure sectors. The…
The Cybersecurity and Infrastructure Security Agency (CISA) has disclosed a significant security vulnerability in the Airleader Master software, which could potentially impact industrial control systems across various critical infrastructure sectors. The vulnerability, identified as CVE-2026-1358, affects all versions up to and including 6.381 and has been assigned a maximum CVSS score of 9.8, indicating a high level of risk.
The issue arises from the unrestricted upload of files with dangerous types, allowing attackers to upload and execute malicious files on affected systems without proper validation. Successful exploitation of this vulnerability could enable attackers to gain full control over compromised industrial control systems. This could disrupt operations in sectors such as chemical plants, manufacturing facilities, energy infrastructure, food production, healthcare systems, transportation networks, and water treatment facilities globally.
CVE ID CVSS Score Vulnerability Type Affected Version
CVE-2026-1358 9.8 (Critical) Unrestricted Upload of File with Dangerous Type Airleader Master ≤6.381
Successful exploitation of this vulnerability could enable attackers to gain full control over compromised industrial control systems.
The extensive deployment of the affected systems in critical sectors raises significant concerns. Organizations using vulnerable versions are advised to take immediate protective measures to mitigate potential risks. Angel Lomeli, a security researcher at SySS GmbH, discovered and reported the vulnerability to CISA, which issued an advisory on Thu, Feb 12, 2026. To date, CISA has not received reports of active exploitation of this vulnerability in the wild.
CISA strongly advises organizations to implement defensive actions promptly to minimize exposure. Key recommendations include:
Ensure control system devices are not accessible from the internet. Position control networks behind firewalls and isolate them from business networks. Use updated VPN solutions for secure remote access.
Organizations should conduct impact analyses and risk assessments before deploying defensive strategies. CISA emphasizes employing defense-in-depth strategies, including network segmentation, access controls, and continuous monitoring for suspicious activities. Organizations are encouraged to review CISA's publicly available guidance on best practices for industrial control system security and cyber intrusion detection strategies.
Any organization detecting potential malicious activity should follow internal incident response procedures and report findings to CISA for correlation with other incidents. Immediate action is essential given the critical severity of the vulnerability and its potential impact on essential infrastructure operations.
Based on reporting by GBHackers.
