What is CVE-2026-35226?
CVE-2026-35226 is an out-of-bounds write vulnerability in the CODESYS PROFINET Controller that allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data, triggering an exception in the affected PLC application. This can disrupt controller functions and impact industrial processes. Network segmentation should be enforced and the vendor security update must be applied immediately.
Azərbaycanca: CVE-2026-35226 CODESYS PROFINET Controller-da autentifikasiya olunmamış təcavüzkara eyni şəbəkə seqmentində xüsusi hazırlanmış PROFINET məlumatları göndərərək PLC tətbiqində "out‑of‑bounds write" zəifliyi vasitəsilə istisna vəziyyəti yaratmağa imkan verir. Bu, cihazın nəzarətçi funksiyalarını pozaraq istehsal proseslərinə təsir göstərə bilər. Şəbəkə seqmentasiyası tətbiq edilməli və istehsalçı tərəfindən təqdim edilən təhlükəsizlik yeniləməsi təcili quraşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-787
FAQ1
Under what conditions can an attacker exploit CVE-2026-35226?
The attacker can exploit the vulnerability unauthenticated, provided they are on the same network segment as the target device and send malformed PROFINET communication data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.