CISA recommends minimizing network exposure for all control system devices and ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. Use VPNs for remote access, updated to the most current version. Perform proper impact analysis and risk assessment prior to deploying defensive measures. Contact PayRange customer support at support@payrange.com for additional information. Note: PayRange has not responded to requests to work with CISA to mitigate this vulnerability.
Quick answers
What is CVE-2026-18965?
CISA recommends minimizing network exposure for all control system devices and ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. Use VPNs for remote access, updated to the most current version. Perform proper impact analysis and risk assessment prior to deploying defensive measures. Contact PayRange customer support at support@payrange.com for additional information. Note: PayRange has not responded to requests to work with CISA to mitigate this vulnerability.
How severe is CVE-2026-18965?
high, CVSS 8.8
Is CVE-2026-18965 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-18965 be mitigated?
CISA recommends minimizing network exposure for all control system devices and ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. Use VPNs for remote access, updated to the most current version. Perform proper impact analysis and risk assessment prior to deploying defensive measures. Contact PayRange customer support at support@payrange.com for additional information. Note: PayRange has not responded to requests to work with CISA to mitigate this vulnerability.
CVSS
8.8
Vendor
PayRange
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
PayRange API
Mitigation
CISA recommends minimizing network exposure for all control system devices and ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. Use VPNs for remote access, updated to the most current version. Perform proper impact analysis and risk assessment prior to deploying defensive measures. Contact PayRange customer support at support@payrange.com for additional information. Note: PayRange has not responded to requests to work with CISA to mitigate this vulnerability.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an industrial control systems advisory (ICS-26-237-04) regarding a missing authorization vulnerability in the PayRange API. The flaw, tracked as CVE-2026-18965, affects all versions of the PayRange API and carries a CVSS 3.1 base score of 8.8. Successful exploitation could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify devices, cause denial of service, or alter a device's displayed image. The vulnerability stems from missing proper authorization on management endpoints, making verbose details of every device on the PayRange network publicly accessible, with or without an account. CISA reports that PayRange has not responded to requests to coordinate mitigation, and no known public exploitation has been reported to CISA at this time.