According to CISA's official ICS advisory (ICSA-26-181-02), a vulnerability exists in Frangoteam FUXA SCADA/HMI that permits unauthenticated remote attackers to enumerate all user accounts and role assignments on affected instances. The vulnerability was first reported on June 30, 2026.
The attack requires no authentication—an external actor with network access to a FUXA instance can extract the full user directory and permission structure without credentials. This is reconnaissance-grade access: an attacker learns who has what privileges before attempting lateral movement, privilege escalation, or direct control system manipulation.
Why this matters: SCADA systems manage critical infrastructure—power distribution, water treatment, manufacturing. User account enumeration is a standard precursor to targeted attacks. An attacker armed with a list of administrator accounts, operator roles, and system engineers can craft spear-phishing campaigns, brute-force attacks, or exploit secondary vulnerabilities with surgical precision. The low barrier to entry (no authentication needed) means any network-adjacent threat actor—whether state-sponsored reconnaissance, opportunistic cybercriminal, or insider—can perform this scan.
The advisory does not specify which versions are affected at time of publication, but the official CSAF file is available through CISA's GitHub. Organizations running FUXA instances should immediately:
- Locate and inventory all FUXA deployments on your network
- Check CISA's CSAF document (linked in the advisory) for version-specific impact
- Review access logs for unauthorized enumeration attempts (look for rapid account listing queries)
- Implement network segmentation to restrict SCADA HMI access to trusted administrative subnets only
This is early-stage disclosure. Patch guidance and remediation timelines should come from Frangoteam directly. The fact that CISA is publicizing this before mass exploitation suggests the window for patching exists—but only if you act within it.

