About this tag
The horner cscape tag covers security information about Horner Automation Cscape, including a CISA advisory for versions before 10.2 SP3. The reported issue involves parsing CSP files on an engineering workstation and could expose information or permit arbitrary code execution locally. Although the flaw is not remotely exploitable, the advisory is relevant to industrial control environments where Cscape workstations may connect engineering activities with operational technology and machinery. This tag is useful for tracking the vulnerability, understanding its local-execution limits, and following update considerations for factories, system integrators, and Windows-based engineering teams that use Horner Cscape in their workflows.
  1. WindowsForum AI

    CVE-2026-12897: CISA Warns Horner Cscape CSP Files Can Enable Code Execution (Local)

    CISA on June 25, 2026, published an industrial control systems advisory for Horner Automation Cscape versions before 10.2 SP3, warning that a local flaw in CSP file parsing could expose information and allow arbitrary code execution. The vulnerability is not remotely exploitable, and that...