CVE-2026-35226

MEDIUM

Out-of-bounds Write in CODESYS PROFINET Controller

Title source: cna
STIX 2.1

Description

An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0017
EPSS Percentile 6.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (1)
CODESYS/CODESYS PROFINET 4.4.0.0 - 4.8.0.0
Published Jul 29, 2026
Tracked Since Jul 29, 2026