Critical Airleader Vulnerability Exposes Systems to Remote Code Execution Attacks
An identified vulnerability in an industrial control system (ICS) monitoring solution has raised concerns across various critical infrastructure sectors.
An identified vulnerability in an industrial control system (ICS) monitoring solution has raised concerns across various critical infrastructure sectors.
Published by the Cybersecurity and Infrastructure Security Agency (CISA) under advisory code ICSA-26-043-10, the flaw has been assigned CVE-2026-1358 with a CVSS v3 score of 9.8, indicating critical severity.
According to the advisory released on Tue, Feb 12, 2026, the vulnerability affects all versions of Airleader Master up to 6.381. It could enable unauthenticated attackers to execute arbitrary code on target systems remotely.
The issue is due to an unrestricted file upload weakness, allowing the upload of executable file types on the device.
CVE ID CVSS Score Vendor Equipment Vulnerability Type Affected Version
An identified vulnerability in an industrial control system (ICS) monitoring solution has raised concerns across various critical infrastructure sectors.
CVE-2026-1358 9.8 (Critical) Airleader GmbH Airleader Master Unrestricted Upload of File with Dangerous Type ≤ 6.381
The vulnerability resides in the file handling component of Airleader Master, developed by Germany-based Airleader GmbH. Successful exploitation enables adversaries to gain control over vulnerable servers or network-connected systems.
This vulnerability poses potential disruption risks to operations in energy, chemical, healthcare, food and agriculture, manufacturing, transportation, and water management sectors. Although there are currently no known public exploits targeting this flaw, the potential for damage is significant due to the widespread use of Airleader Master for industrial system optimization and monitoring.
CISA advises system administrators and operators of critical infrastructure to take immediate steps to reduce exposure by:
Restricting network access to ensure control systems are not accessible from the internet. Segmenting ICS networks and placing them behind properly configured firewalls. Using VPNs for remote access, ensuring they are fully updated and hardened. Conducting impact assessments and risk analyses before implementing new defensive measures.
CISA also recommends following its Industrial Control System (ICS) cybersecurity best practices. Guidance documents include Improving ICS Cybersecurity with Defense-in-Depth Strategies and ICS-TIP-12-146-01B: Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations detecting suspicious activity associated with this vulnerability should report it to CISA for coordinated analysis and response.
Based on reporting by Cyber Security News.
