๐Ÿ” CVE Alert

CVE-2026-35225

UNKNOWN 0.0

Improper timeout handling in CODESYS EtherNetIP

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate clients from establishing new connections.

CWE CWE-754
Vendor codesys
Product codesys ethernetip
Published Apr 23, 2026
Last Updated Apr 23, 2026
Stay Ahead of the Next One

Get instant alerts for codesys codesys ethernetip

Be the first to know when new unknown vulnerabilities affecting codesys codesys ethernetip are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

CODESYS / CODESYS EtherNetIP
1.0.0.0 < 4.9.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
codesys.csaf-tp.certvde.com: https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-04_vde-2026-040.json certvde.com: https://www.certvde.com/en/advisories/VDE-2026-040/

Credits

๐Ÿ” ABB