CISA has issued an advisory for All-Line Equipment Company Fuel-Boss systems affected by two critical CVEs: CVE-2018-19518 (argument injection via IMAP Toolkit in PHP) and CVE-2019-11043 (PHP-FPM buffer overflow enabling remote code execution). All Fuel-Boss V1 variants running PHP 7.1.5 or earlier are affected, including Standard, Portal, Master/Slave, and Backflush Systems configurations. Successful exploitation could allow remote attackers to execute arbitrary OS commands or code. Fixes are available for V1 Standard and V1 Portal; no fix is yet available for Master/Slave, and no fix is planned for Backflush Systems. CISA recommends isolating affected systems from the internet, deploying firewalls, and using VPNs for remote access. Affected critical infrastructure sectors include Critical Manufacturing, Defense Industrial Base, Emergency Services, and Transportation Systems. The advisory was initially published on 2026-08-27 and vulnerabilities were anonymously reported to CISA.