CVE-2026-22918
CVE-2026-22918
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
15 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected products
SICK AG · TDC-X401GLWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://sick.com/psirthttps://www.cisa.gov/resources-tools/resources/ics-recommended-practiceshttps://www.first.org/cvss/calculator/3.1https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdfhttps://www.sick.com/.well-known/csaf/white/2026/sca-2026-0001.jsonhttps://www.sick.com/.well-known/csaf/white/2026/sca-2026-0001.pdf