CISA published an ICS advisory for CVE-2026-18965, a missing authorization vulnerability (CWE-862) in all versions of the PayRange API. The flaw exposes management endpoints without proper access controls, allowing remote attackers to disclose sensitive information about every device on the PayRange network, modify device settings to cause denial of service, or alter displayed images. The CVSS v3.1 score is 8.8 (HIGH). PayRange has not responded to CISA coordination efforts, leaving no vendor-supplied patch available.
PayRange API
1 post
PayRange API (CVE-2026-18965)