SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-35226

MEDIUM · CVSS 6.5 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

An out-of-bounds write vulnerability in the CODESYS PROFINET Controller allows unauthenticated attackers on the same network segment to exploit malformed PROFINET communication data, leading to a controlled stop of the PLC application. This could disrupt operational processes and potentially lead to downtime in industrial environments. Organizations using CODESYS for PLC applications should prioritize patching this vulnerability to mitigate risks associated with network-based attacks.

CVE
CVE-2026-35226
Severity
MEDIUM
CVSS
6.5
EPSS
0.17%

Original NVD Description

An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.