CVE-2026-3509
EUVD-2026-1478424.03.2026, 08:16
An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| codesys | control_rte_sl | 3.5.17.0 ≤ 𝑥 < 3.5.22.0 | CNA |
| codesys | control_rte_sl | 4.1.0.0 ≤ 𝑥 < 4.21.0.0 | CNA |
Common Weakness Enumeration