What happened
On August 27, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) released an advisory concerning vulnerabilities in All-Line Equipment Company's Fuel-Boss systems. The advisory identifies multiple affected product versions, including Fuel-Boss V1 Standard, V1 Portal, V1 Master/Slave, and V1 Backflush Systems, all running PHP version 7.1.5. The vulnerabilities are associated with CVE-2018-19518 and CVE-2019-11043, and carry a CVSS v3 score of 8.7.
Why it matters
Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. This poses a significant risk to organizations using Fuel-Boss equipment, potentially leading to unauthorized access, data breaches, or disruption of operations. The advisory underscores the importance of applying patches or mitigations promptly.