<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:08:02 +0000</lastBuildDate>
    <item>
      <title>Advisory2026-05_VDE-2026-042 — CODESYS Modbus TCP Server - Improper resource management</title>
      <link>https://cve.radiocsirt.org/vuln/advisory2026-05_vde-2026-042</link>
      <description>&lt;p&gt;CODESYS Modbus is an add‑on for the CODESYS Development System that provides a fully integrated Modbus protocol stack along with diagnostic capabilities. A flaw in the CODESYS Modbus TCP Server protocol stack library results in a vulnerability. When a Modbus TCP server is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.&lt;/p&gt;
&lt;p&gt;The vulnerability is caused by a resource management issue in the Modbus TCP server and is only exploitable if a race condition in the connection handling is successfully triggered. Over time, this may exhaust the configured maximum number of connections, potentially preventing new connections from being accepted. Existing connections remain unaffected and continue to operate normally.&lt;/p&gt;
&lt;p&gt;This issue affects only CODESYS projects that include a Modbus TCP server configuration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CODESYS Modbus is an add‑on for the CODESYS Development System that provides a fully integrated Modbus protocol stack along with diagnostic capabilities. A flaw in the CODESYS Modbus TCP Server protocol stack library results in a vulnerability. When a Modbus TCP server is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.&lt;/p&gt;
&lt;p&gt;The vulnerability is caused by a resource management issue in the Modbus TCP server and is only exploitable if a race condition in the connection handling is successfully triggered. Over time, this may exhaust the configured maximum number of connections, potentially preventing new connections from being accepted. Existing connections remain unaffected and continue to operate normally.&lt;/p&gt;
&lt;p&gt;This issue affects only CODESYS projects that include a Modbus TCP server configuration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/advisory2026-05_vde-2026-042</guid>
    </item>
    <item>
      <title>EUVD-2026-318026</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-318026</link>
      <description>EUVD-2026-318026</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-318026</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35227</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35227</link>
      <description>&lt;p&gt;An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35227</guid>
    </item>
    <item>
      <title>GHSA-qc33-pwh4-j9rq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qc33-pwh4-j9rq</link>
      <description>&lt;p&gt;An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qc33-pwh4-j9rq</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1464 — CODESYS Modbus: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1464</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in CODESYS Modbus ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in CODESYS Modbus ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1464</guid>
    </item>
  </channel>
</rss>
