← Knowledge Center
Advisory CVE-2026-56415, CVE-2026-55721, CVE-2026-50040, CVE-2026-50110, CVE-2026-56413

StoneFly Storage Concentrator flaws include hard-coded credentials, CVSS 10

CISA published an ICS advisory for StoneFly Storage Concentrator and its virtual machine variant, covering multiple vulnerabilities rated up to CVSS 10. The most identity-relevant issue is the use of hard-coded credentials, which can grant attackers broad unauthorized access without legitimate authentication. Additional flaws include OS command injection, SQL injection, and cross-site scripting.

Successful exploitation could let attackers execute arbitrary commands with root privileges, exfiltrate sensitive data, and act on behalf of legitimate users across interconnected systems. Affected versions span several fix thresholds (8.0.4.22, 8.0.4.26, and 8.0.4.29), and the products are deployed in critical infrastructure sectors including the Defense Industrial Base and Energy.

What to take away: Hard-coded credentials are a classic identity weakness that bypasses access controls entirely; organizations running these appliances should patch to the fixed builds and audit for any signs of unauthorized root access or credential abuse.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.