CVE-2026-42933
Pronetiqs IntraVUE versions 3.2.1a14 and earlier contain a proxy vulnerability that lets an attacker use an active proxy to bypass OT segmentation. The flaw is critical because it can be exploited remotely without authentication or user interaction.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Pronetiqs IntraVUE 3.2.1a14 and earlier, typically used by industrial control system operators.
Real-world impact
An attacker could set up an active proxy to circumvent network segmentation, potentially accessing and controlling critical industrial control network components.
Why this severity
The CVSS score of 10 reflects that the vulnerability is remotely exploitable with no authentication, no user interaction, and grants full compromise of confidentiality, integrity, and availability, making it a top‑tier threat.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 23, 2026 · 8d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoAdvisory updatedThe NVD record was last revised.