CrowdSecLive Exploit Tracker
Active ExploitationCVE-2026-47717Public Exploit

FUXA - Information Disclosure (CVE-2026-47717)

PublishedMay 27, 2026
First SeenJun 25, 2026
Last Seen
Reported
enterprise_software

Description

The GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled.

psychologyCrowdSec Analysis

CVE-2026-47717 is a newly identified vulnerability, but specific details regarding its nature, affected components, and potential impact have not yet been disclosed. As information becomes available, organizations should monitor official advisories to assess risk and determine appropriate mitigation steps.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

CrowdSec network data shows that most actors exploiting CVE-2026-47717 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature. Telemetry from the CrowdSec network also shows that exploitation activity for CVE-2026-47717 remains steady week-over-week. Attack volumes are consistent with long-term trends, indicating sustained interest from threat actors. CVE-2026-47717 continues to be an active part of the threat landscape and will likely remain this way for the forseeable future.

Attackers exploit unauthenticated access to the /api/project endpoint on FUXA servers, allowing them to retrieve sensitive ICS/SCADA project configuration data without credentials.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-05-27
Rule Released2026-06-24
CrowdSec First Seen2026-06-25

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.