CVE-2026-19471
View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other...
Affects 0 products across 1 vendor.
Attacker injects malicious scripts into web pages viewed by other users, executing in the victim's browser context.
Show all 6
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A unscored severity vulnerability (CVE-2026-19471) affects the target system. Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when oth...
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-19471?
Is CVE-2026-19471 actively exploited?
How do I remediate CVE-2026-19471?
What systems are affected by CVE-2026-19471?
| CVE ID | CVE-2026-19471 |
|---|---|
| Published | 2026-09-01 |
| Last Modified | 2026-09-03 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Source | NVD |
View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT <=v2.001 (CVE-2026-19471, CVE-2026-19472) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ArmorStart LT Improper Neutralization of Input During W
Source: NIST NVD / MITRE CVE Database
| Vendor | Product | Fixed Version |
|---|---|---|
| Rockwell Automation | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.
Create a free account →