Out-of-Bounds Write Vulnerability in CODESYS PROFINET Controller by CODESYS
CVE-2026-35226

7.1HIGH

Key Information:

Vendor

Codesys

Vendor
CVE Published:
29 July 2026

What is CVE-2026-35226?

This vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to exploit malformed PROFINET communication data. When this data is sent, it triggers an exception within the affected PLC application, which is managed by the CODESYS Control runtime system. As a result, the PLC application can experience a controlled stop, disrupting operations and presenting a potential security risk. Organizations using this controller should implement measures to mitigate the impact of this vulnerability.

Affected Version(s)

CODESYS PROFINET 4.4.0.0 < 4.8.0.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABB
.