Cyber Resilience
← All news
Confirmed

PayRange API

Our takeCISA's ICSA-26-237-04 reports active exploitation in all versions of the PayRange API: remote attackers can disclose sensitive data, cause DoS, or alter device displays. Update or isolate every affected system now.
Sources (1)
What this means for you — Security leader:CISA ICSA-26-237-04 confirms active exploitation of the PayRange API affecting all versions. If you operate, integrate, or rely on PayRange vending or payment kiosks, isolate them, review authentication controls, and apply any vendor mitigations immediately.
What this means for you — Lean IT orgs:If you use PayRange machines in your office, lobby, or break room, assume they can be remotely tampered with right now. Contact your vendor or the location owner and ask what they are doing to lock it down or replace the units.
What this means for you — MSP:PayRange API (all versions) is under active exploitation per CISA. Scan client environments for any PayRange integrations or kiosks; treat them as internet-exposed attack surface and apply vendor guidance or network isolation now.
What this means for you — Researcher:CISA reports active exploitation of the PayRange API (all versions). Successful attacks let an unauthenticated remote actor leak sensitive data, modify devices, cause denial of service, or change displayed images.