Cyber Resilience
← All news
Confirmed

PayRange API

Our takeCISA reports active exploitation in all versions of the PayRange API: remote attackers can disclose sensitive information, cause denial of service, or alter the displayed image. Update or mitigate now if you run these devices.
Sources (1)
What this means for you — Security leader:CISA's ICSA-26-237-04 reports active exploitation in all versions of the PayRange API: remote attackers can disclose sensitive data, cause DoS, or alter device displays. Update or isolate every affected system now.
What this means for you — Lean IT orgs:If you use PayRange for vending or device payments, this affects every version. Update the API or isolate the devices immediately.
What this means for you — MSP:All PayRange API versions are under active exploitation per CISA ICSA-26-237-04. Review every client using it and update or isolate the affected devices now.
What this means for you — Researcher:CISA ICSA-26-237-04 lists active exploitation of the PayRange API (all versions). Remote attackers can disclose data, DoS devices, or change displayed images.