<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:20:24 +0000</lastBuildDate>
    <item>
      <title>Advisory2026-06_VDE-2026-041 — CODESYS PROFINET Controller - Out-of-bounds Write</title>
      <link>https://cve.radiocsirt.org/vuln/advisory2026-06_vde-2026-041</link>
      <description>&lt;p&gt;CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.&lt;/p&gt;
&lt;p&gt;The vulnerability in the CODESYS PROFINET Controller is caused by an out‑of‑bounds write during the processing of received invalid PROFINET communication data. Triggering this condition causes the CODESYS Control runtime system to handle the resulting exception and stop the affected PLC application in a controlled manner. Remote code execution is not considered feasible, as the execution flow remains controlled.&lt;/p&gt;
&lt;p&gt;This issue affects only CODESYS projects that include a PROFINET Controller configuration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.&lt;/p&gt;
&lt;p&gt;The vulnerability in the CODESYS PROFINET Controller is caused by an out‑of‑bounds write during the processing of received invalid PROFINET communication data. Triggering this condition causes the CODESYS Control runtime system to handle the resulting exception and stop the affected PLC application in a controlled manner. Remote code execution is not considered feasible, as the execution flow remains controlled.&lt;/p&gt;
&lt;p&gt;This issue affects only CODESYS projects that include a PROFINET Controller configuration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/advisory2026-06_vde-2026-041</guid>
    </item>
    <item>
      <title>EUVD-2026-342371</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342371</link>
      <description>EUVD-2026-342371</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342371</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35226</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35226</link>
      <description>&lt;p&gt;An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35226</guid>
    </item>
    <item>
      <title>GHSA-jxhr-7f6w-54g7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jxhr-7f6w-54g7</link>
      <description>&lt;p&gt;An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jxhr-7f6w-54g7</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2555 — CODESYS: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2555</link>
      <description>&lt;p&gt;Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in CODESYS ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in CODESYS ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2555</guid>
    </item>
  </channel>
</rss>
