LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-21718

CVE-2026-21718 - Vulnerability Analysis

CriticalCVSS: 10.0

Last Updated: February 27, 2026

Copeland XWEB Pro - Authentication Bypass

Published: February 27, 2026Updated: February 27, 2026Remote Exploitable

Overview

Copeland XWEB Pro <= 1.12.1 contains an authentication bypass vulnerability caused by improper authentication checks, letting attackers bypass authentication and execute code pre-authentication.

Severity & Score

Severity: Critical
CVSS Score: 10.0
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can bypass authentication and execute code without prior access, potentially compromising the entire system.

Mitigation

Update to the latest version beyond 1.12.1.

Social Media Activity(2 posts)

Offensive Sequence
Offensive Sequence
@offseq
Feb 27, 2026

🚨 CVE-2026-21718: CRITICAL auth bypass in Copeland XWEB 300D PRO (≤1.12.1). Remote code exec possible — no user interaction. No patch yet. Segment & monitor ICS networks! https://radar.offseq.com/threat/cve-2026-21718-cwe-327-in-copeland-copeland-xweb-3-124474ba #OffSeq #ICS #Vulnerability #Cybersecurity

View original post
Offensive Sequence
Offensive Sequence
@offseq
Feb 27, 2026

🚨 CVE-2026-21718: CRITICAL auth bypass in Copeland XWEB 300D PRO (≤1.12.1). Remote code exec possible — no user interaction. No patch yet. Segment & monitor ICS networks! https://radar.offseq.com/threat/cve-2026-21718-cwe-327-in-copeland-copeland-xweb-3-124474ba #OffSeq #ICS #Vulnerability #Cybersecurity

View original post

Details

CVE ID
CVE-2026-21718
Severity
Critical
CVSS Score
10.0
Type
broken_authentication
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-327

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days