CriticalCISAAug 25, 2026

PayRange API

View CSAF Summary Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image. The following versions of PayRange API are affected: PayRange API vers:all/* CVSS Vendor Equipment Vulnerabilities v3 8.8 PayRange PayRange API Missing Authorization Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: United States, Canada Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-18965 The affected product is missing proper authorization on management endpo

Why it matters

This item has practical defensive relevance and is worth validating against your asset inventory, telemetry and patch state.

What defenders should do

Identify affected versions, prioritize internet-facing systems, and apply the vendor remediation.

Verify at the source

CyberKit curates and prioritizes; the source remains authoritative. Read the original advisory at www.cisa.gov →

Need to validate an indicator or network range?
Move from reading to action with the free CyberKit toolbox.
Use security tools