Remote Code Execution Vulnerability in CODESYS Control Runtime by CODESYS GmbH
CVE-2026-3509

7.5HIGH

What is CVE-2026-3509?

An unauthenticated remote attacker has the potential to manipulate the format string of messages within the Audit Log of the CODESYS Control runtime system. This manipulation may allow the attacker to trigger a denial-of-service condition, interrupting the normal operation of the system and potentially leading to further exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CODESYS Control for BeagleBone SL 4.1.0.0 < 4.21.0.0

CODESYS Control for emPC-A/iMX6 SL 4.1.0.0 < 4.21.0.0

CODESYS Control for IOT2000 SL 4.1.0.0 < 4.21.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.