Remote Code Execution Vulnerability in CODESYS Control Runtime by CODESYS GmbH
CVE-2026-3509
7.5HIGH
What is CVE-2026-3509?
An unauthenticated remote attacker has the potential to manipulate the format string of messages within the Audit Log of the CODESYS Control runtime system. This manipulation may allow the attacker to trigger a denial-of-service condition, interrupting the normal operation of the system and potentially leading to further exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CODESYS Control for BeagleBone SL 4.1.0.0 < 4.21.0.0
CODESYS Control for emPC-A/iMX6 SL 4.1.0.0 < 4.21.0.0
CODESYS Control for IOT2000 SL 4.1.0.0 < 4.21.0.0
