CISA has published an ICS advisory regarding a critical Missing Authorization vulnerability (CVE-2026-18965) affecting all versions of the PayRange API. The flaw allows remote attackers, authenticated or unauthenticated, to disclose sensitive device information, cause denial of service, or alter displayed images on devices. The vulnerability carries a CVSS v3.1 score of 8.8 (HIGH) and a CVSS v4.0 score of 8.7 (HIGH). All versions of PayRange API are affected, with deployment in the United States and Canada, primarily in the Commercial Facilities critical infrastructure sector. PayRange has not responded to CISA's requests to work on mitigation. Users are advised to contact PayRange support and follow CISA's recommended defensive practices, including minimizing network exposure and using VPNs for remote access. No known public exploitation has been reported at this time. The vulnerability was reported by Tahi Wilton Geary.