Update ANDRITZ HIPASE-250/250 SCALA to version V8.15.00 or later. If immediate updating is not possible, network segmentation and monitoring of unauthorized access to device endpoints are recommended. Contact ANDRITZ at https://www.andritz.com/group-en/contact for patch guidance.
Quick answers
What is CVE-2026-65309?
Update ANDRITZ HIPASE-250/250 SCALA to version V8.15.00 or later. If immediate updating is not possible, network segmentation and monitoring of unauthorized access to device endpoints are recommended. Contact ANDRITZ at https://www.andritz.com/group-en/contact for patch guidance.
How severe is CVE-2026-65309?
high, CVSS 8.7
Is CVE-2026-65309 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-65309 be mitigated?
Update ANDRITZ HIPASE-250/250 SCALA to version V8.15.00 or later. If immediate updating is not possible, network segmentation and monitoring of unauthorized access to device endpoints are recommended. Contact ANDRITZ at https://www.andritz.com/group-en/contact for patch guidance.
CVSS
8.7
Vendor
ANDRITZ
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
ANDRITZ HIPASE-250, ANDRITZ 250 SCALA
Mitigation
Update ANDRITZ HIPASE-250/250 SCALA to version V8.15.00 or later. If immediate updating is not possible, network segmentation and monitoring of unauthorized access to device endpoints are recommended. Contact ANDRITZ at https://www.andritz.com/group-en/contact for patch guidance.
CISA and ANDRITZ have disclosed four vulnerabilities affecting ANDRITZ HIPASE-250 and 250 SCALA industrial control system software versions 7.20 and earlier. The flaws span reversible password storage, unauthenticated data exposure, an undocumented logging-level endpoint, and a hard-coded x11vnc password in provisioning scripts. ANDRITZ has released patches in versions V8.00.00 (December 2024) and V8.15.00 (July 2026), urging users to update immediately.