← All Advisories

CVE-2026-79625

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-79625

Key Details

CVECVE-2026-79625
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-30
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
CODESYSControl RTE (SL)
CODESYSControl RTE (for Beckhoff CX) SL
CODESYSControl Win (SL)
CODESYSRuntime Toolkit
CODESYSSafety SIL2
CODESYSHMI (SL)
CODESYSDevelopment System 3
CODESYSControl for BeagleBone SL
CODESYSControl for emPC-A/iMX6 SL
CODESYSControl for IOT2000 SL
CODESYSControl for Linux ARM SL
CODESYSControl for Linux SL
CODESYSControl for PFC100 SL
CODESYSControl for PFC200 SL
CODESYSControl for PLCnext SL
CODESYSControl for Raspberry Pi SL
CODESYSControl for WAGO Touch Panels 600 SL
CODESYSVirtual Control SL
SubsystemsGeneral OT
SectorsMultiple

What to Know

Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition. (NVD)

What to Do

Monitor CODESYS's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-79625
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-79625