CVE-2026-3509
7.5CODESYS · CODESYS Control
An unauthenticated remote attacker can trigger a denial-of-service condition in the CODESYS Control runtime system by exploiting an externally-controlled format string vulnerability in the Audit Log.
Executive summary
A critical format string vulnerability in the CODESYS Control runtime allows unauthenticated remote attackers to cause a denial-of-service condition.
Vulnerability
The flaw is an improper use of an externally-controlled format string (CWE-134) within the Audit Log processing function, which can be triggered by an unauthenticated attacker to crash the runtime system.
Business impact
The exploitation of this vulnerability results in a denial-of-service condition, which can lead to significant operational downtime for industrial control systems relying on the affected CODESYS runtime. Given the CVSS score of 7.5, the risk is classified as High, particularly for environments where system availability is critical for safety or production continuity.
Remediation
Immediate Action: Update the affected CODESYS runtime components to version 3.5.22.0 or 4.21.0.0, respectively, as specified in the vendor advisory.
Proactive Monitoring: Monitor system logs for repeated crashes or unusual error patterns within the Audit Log service that may indicate attempted exploitation.
Compensating Controls: Restrict network access to the CODESYS runtime interface using firewalls or VPNs to ensure that only authorized personnel can reach the vulnerable service.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
System administrators must prioritize the deployment of the provided vendor patches to eliminate the format string vulnerability. Given the ease of exploitation, ensure that all internet-facing instances of CODESYS Control are secured behind robust network perimeters while the update process is completed.