Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2026-097
Sept. 30, 2026, 12:00 PM
The monitoring functionality of affected CODESYS Control runtime systems processes read and write requests to PLC application data sent by the CODESYS Development System and other clients such as HMIs. …
VDE-2026-094
Sept. 30, 2026, 12:00 PM
The CODESYS Gateway Client (CmpGatewayClient) is used by various CODESYS products to establish PLC communication via the CODESYS Gateway. Due to missing limits on memory allocations derived from a size …
VDE-2026-041
July 29, 2026, 12:00 PM
CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable …
VDE-2026-040
July 13, 2026, 12:00 PM
CODESYS EtherNet/IP is an add‑on for the CODESYS Development System that provides a fully integrated EtherNet/IP protocol stack along with diagnostic capabilities. A flaw in the EtherNet/IP adapter protocol stack …
VDE-2026-057
June 18, 2026, 12:00 PM
The CmpWebServer component in the CODESYS Control Runtime allows users to create browser-based visualizations for monitoring and controlling industrial processes. Due to improper bounds checking, a specially crafted HTTP request …
VDE-2026-055
May 26, 2026, 12:00 PM
Two local privilege escalation vulnerabilities were identified in the CODESYS Development System. Specifically, the PackageManager and the IPM create temporary directories with insecure default permissions when executed with administrative privileges. …
VDE-2026-056
June 18, 2026, 12:00 PM
The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups including the visualization administrators group, which is intended solely to manage visualization users. Due to insufficient …
VDE-2026-052
May 21, 2026, 12:00 PM
A vulnerability in the CODESYS Visualization login dialog has been identified. During logins within the CODESYS Visualization, authentication data may not be sufficiently isolated when multiple users perform login operations …