Out-of-Bounds Write Vulnerability in CODESYS PROFINET Controller by CODESYS
CVE-2026-35226
7.1HIGH
What is CVE-2026-35226?
This vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to exploit malformed PROFINET communication data. When this data is sent, it triggers an exception within the affected PLC application, which is managed by the CODESYS Control runtime system. As a result, the PLC application can experience a controlled stop, disrupting operations and presenting a potential security risk. Organizations using this controller should implement measures to mitigate the impact of this vulnerability.
Affected Version(s)
CODESYS PROFINET 4.4.0.0 < 4.8.0.0
