High severityNVD Advisory· Published Jun 25, 2026· Updated Jun 25, 2026
CVE-2026-12897
CVE-2026-12897
Description
Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code.
Affected products
1- Range: <10.2 SP3
Patches
Vulnerability mechanics
References
1News mentions
1- Horner Automation CscapeCISA ICS Advisories