CVE-2026-35226: Out-of-bounds Write in CODESYS PROFINET Controller
An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35226?
The severity of CVE-2026-35226 is rated as medium with a score of 6.5.
How do I fix CVE-2026-35226?
To fix CVE-2026-35226, ensure that your CODESYS PROFINET Controller software is updated to the latest version provided by the vendor.
What are the risks associated with CVE-2026-35226?
CVE-2026-35226 allows an unauthenticated attacker to potentially disrupt the affected PLC application through malformed PROFINET communication.
Who is affected by CVE-2026-35226?
Any organization utilizing the vulnerable version of CODESYS PROFINET Controller in their network may be exposed to CVE-2026-35226.
What type of vulnerability is CVE-2026-35226?
CVE-2026-35226 is classified as an out-of-bounds write vulnerability.