Status: UPDATED
| Advisory ID: CVE-2026-79625
Key Details
| CVE | CVE-2026-79625 |
| CVSS Score / Version | 8.1 (High) / CVSS v3.1 |
| Updated | 2026-09-30 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high. |
| Affected products | see table below |
| Classified as | CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition. (NVD)
What to Do
Monitor CODESYS's web page for any future patch releases.
References