๐Ÿ” CVE Alert

CVE-2026-79625

HIGH 8.1

Improper Synchronization in Monitoring in CODESYS Control Runtime

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.

CWE CWE-362
Vendor codesys
Product control rte (sl)
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for codesys control rte (sl)

Be the first to know when new high vulnerabilities affecting codesys control rte (sl) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

CODESYS / Control RTE (SL)
3.0.0.0 < 3.5.22.40
CODESYS / Control RTE (for Beckhoff CX) SL
3.0.0.0 < 3.5.22.40
CODESYS / Control Win (SL)
3.0.0.0 < 3.5.22.40
CODESYS / Runtime Toolkit
3.0.0.0 < 3.5.22.40
CODESYS / Safety SIL2
3.0.0.0 < 3.5.22.40
CODESYS / HMI (SL)
3.0.0.0 < 3.5.22.40
CODESYS / Development System 3
3.0.0.0 < 3.5.22.40
CODESYS / Control for BeagleBone SL
3.5.0.0 < 4.23.0.0
CODESYS / Control for emPC-A/iMX6 SL
3.5.0.0 < 4.23.0.0
CODESYS / Control for IOT2000 SL
3.5.0.0 < 4.23.0.0
CODESYS / Control for Linux ARM SL
3.5.0.0 < 4.23.0.0
CODESYS / Control for Linux SL
3.5.0.0 < 4.23.0.0
CODESYS / Control for PFC100 SL
3.5.0.0 < 4.23.0.0
CODESYS / Control for PFC200 SL
3.5.0.0 < 4.23.0.0
CODESYS / Control for PLCnext SL
3.5.0.0 < 4.23.0.0
CODESYS / Control for Raspberry Pi SL
3.5.0.0 < 4.23.0.0
CODESYS / Control for WAGO Touch Panels 600 SL
3.5.0.0 < 4.23.0.0
CODESYS / Virtual Control SL
3.5.0.0 < 4.23.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
certvde.com: https://www.certvde.com/en/advisories/VDE-2026-097/