https://seclists.org/oss-sec/2026/q3/1020: CVE-2026-102511: Apache PLC4X: ADS discovery accepts spoofed sponses and derives the connection target from them
Published Sep 30, 2026
·Updated
Affected Software
4 affected components
Apache PLC4Go>=0.11.0<1.0.0
Apache PLC4J ADS driver>=0.10.0<1.0.0
Apache PLC4J Modbus driver>=0.10.0<1.0.0
Apache PLC4J EtherNet/IP driver>=0.11.0<1.0.0