A critical proxy bypass vulnerability (CVE-2026-42933) has been identified in Pronetiqs IntraVUE platform and appliance versions 3.2.1a14 and earlier. The flaw stems from improper validation of intermediary traffic, permitting attackers to exploit an active proxy and bypass operational technology (OT) network segmentation controls. Successful exploitation could enable unauthorized access to segmented OT environments, facilitating lateral movement and potential disruption of critical infrastructure operations. The CVSS score of 10.0 reflects the vulnerability's high exploitability and severe impact potential. Organizations utilizing affected versions of IntraVUE for network monitoring or industrial control systems are urged to apply vendor-provided patches immediately. Until patched, administrators should implement strict network access controls, monitor for anomalous proxy-related traffic, and segment OT networks using additional firewall rules to mitigate exposure. This vulnerability underscores the importance of maintaining up-to-date configurations in environments where OT and IT systems intersect.
CRITICAL
CVSS 10.0
CVE-2026-42933
2026-08-14
Pronetiqs IntraVUE Proxy Bypass Vulnerability (CVE-2026-42933)
Critical vulnerability in Pronetiqs IntraVUE allows proxy bypass, enabling attackers to circumvent operational technology (OT) network segmentation. Unpatched systems running versions 3.2.1a14 or earlier are at risk of unauthorized access and lateral movement.