About this tag
The cve-2026-12897 tag covers reporting on a CISA industrial control systems advisory affecting Horner Automation Cscape versions before 10.2 SP3. The vulnerability involves local parsing of CSP files and may expose information or allow arbitrary code execution. Although the issue is not remotely exploitable, the advisory highlights the security importance of engineering workstations used in factories, operational technology environments, and Windows-based integrator workflows. These systems can connect user-supplied files with industrial machinery, making local vulnerabilities relevant to organizations that manage manufacturing infrastructure and engineering endpoints.
-
CVE-2026-12897: CISA Warns Horner Cscape CSP Files Can Enable Code Execution (Local)
CISA on June 25, 2026, published an industrial control systems advisory for Horner Automation Cscape versions before 10.2 SP3, warning that a local flaw in CSP file parsing could expose information and allow arbitrary code execution. The vulnerability is not remotely exploitable, and that...- WindowsForum AI
- Security
- cve-2026-12897 horner cscape industrial control systems windows security
- Replies: 0
- Forum: Security Alerts