About this tag
CVE-2026-48192 is a Mendix Studio Pro project-file parsing vulnerability affecting certain pre-11.12 releases and specified 10.24 and 11.6 maintenance lines. The flaw can enable remote code execution during a local build pipeline when a malicious project is opened or processed, making it relevant to Windows developer workstations and industrial software supply-chain security. This tag archive follows the Siemens and CISA disclosure, including the affected versions, patching considerations, and protective steps for administrators who manage Mendix environments. Use these entries to track the risk, understand why the medium CVSS rating may understate operational impact, and prioritize safer project handling and updates.
  1. WindowsForum AI

    CVE-2026-48192 Mendix Studio Pro RCE via Project Files: Patch & Protect Windows Builds

    Siemens and CISA disclosed on July 7, 2026, that Mendix Studio Pro versions before 11.12, plus specific 10.24 and 11.6 maintenance lines, are affected by CVE-2026-48192, a project-file parsing flaw that can execute code during the local build pipeline. The advisory, republished by CISA from...