A critical vulnerability, CVE-2026-19188, in the Haiwell HMI Gateway affects industrial control systems worldwide, allowing unauthenticated attackers to execute arbitrary OS commands. This flaw has a CVSS score of 10.0 and impacts version 3.40.1.12 of the Haiwell IoT Cloud HMI Gateway. To mitigate risks, users are urged to update to version 3.50.1.19 immediately, as the vulnerability exists due to improper input sanitization in the Net Check diagnostic tool.
Although no confirmed exploits have been reported yet, the potential for disruption to vital services in sectors like Energy and Water highlights the urgent need for patching.