ZeroHour

CVE-2026-18780

Cross-Site Request Forgery in Talassoft Industrial Management Software

CVSS 3.1
7.1 high
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-18780 is a cross-site request forgery (CSRF, CWE-352) flaw in Talassoft Industrial Management Software from Turkish vendor TMT Machine Industry and Trade Ltd. Co. An attacker exploits it by tricking an already-authenticated user into loading an attacker-controlled page or link while their browser holds a valid session, causing the browser to silently submit forged state-changing requests to the application. Because the CVSS vector scores integrity impact as high (I:H) with low confidentiality impact, a successful attack primarily allows unauthorized modifications of application data or settings rather than large-scale data disclosure. Any deployment running Talassoft versions from V.4 up to, but not including, V.16 is affected. No public proof-of-concept, KEV listing, or reports of in-the-wild exploitation are known, and EPSS puts the 30-day exploitation probability at roughly 0.1%.

What to do: Upgrade Talassoft Industrial Management Software to V.16 or later, which resolves the flaw for all versions from V.4 onward. Until patched, minimize the attack surface by restricting access to the application to trusted networks and instructing users to avoid browsing other sites while logged in. Check the Turkish national vulnerability database (USOM/FGM) advisory associated with this CVE for vendor patch details.

Affected
TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Softwarefrom V.4 before V.16
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.

Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.