SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-78012

CRITICAL · CVSS 9.8 EPSS 0.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The NetStaX EtherNet/IP Stack versions prior to 5.6.1 are vulnerable to a buffer overflow caused by large Class 3 explicit-message requests, which can lead to memory corruption, device crashes, or potential remote exploitation without any error notifications. Organizations utilizing this stack in their industrial control systems or IoT devices should prioritize patching to mitigate the risk of severe operational disruptions or unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78012
Severity
CRITICAL
CVSS
9.8
EPSS
0.47%

Original NVD Description

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.