CVE-2026-3094

7.8

Delta Electronics · CNCSoft-G2

Delta Electronics CNCSoft-G2 is vulnerable to an out-of-bounds write due to improper file validation, which may allow an attacker to achieve remote code execution by tricking a user into opening a file.

Executive summary

A critical out-of-bounds write vulnerability in Delta Electronics CNCSoft-G2 allows for arbitrary code execution if a user opens a specially crafted malicious file.

Vulnerability

The software fails to properly validate user-supplied files, leading to a CWE-787 out-of-bounds write condition. An unauthenticated attacker can leverage this flaw to execute code in the context of the current process when a victim opens a malicious file.

Business impact

The ability to execute arbitrary code on a host system presents a severe risk to organizational security, potentially leading to total system compromise, data theft, or the installation of persistent malware. With a CVSS score of 7.8, this high-severity vulnerability highlights the danger of file-parsing flaws in industrial software. Successful exploitation could result in significant operational disruption and loss of intellectual property within manufacturing environments.

Remediation

Immediate Action: Update Delta Electronics CNCSoft-G2 to version 2.1.0.39 or later immediately to resolve the vulnerable code path.

Proactive Monitoring: Monitor endpoint activity for unexpected process spawns or unauthorized file access originating from CNCSoft-G2.

Compensating Controls: Implement strict file access controls and utilize security awareness training to prevent users from opening untrusted or unexpected files within the CNC environment.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete system compromise via remote code execution, organizations using CNCSoft-G2 must prioritize this update. Administrators should verify the version currently deployed across all workstations and ensure the transition to version 2.1.0.39 is completed without delay to eliminate the risk of exploitation.

More Delta Electronics CVEs

Sources

Originally found and disclosed by Natnael Samson (@NattiSamson) working with TrendAI Zero Day Initiative, with CISA (coordinator), per the CVE Program record.