{"id":"CVE-2026-79625","title":"Affected products do not properly synchronize access to their monitoring functionality","summary":"Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authen…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-362"],"vendor":"CODESYS","product":"Control RTE (SL)","affected":["control_rte_sl >= 3.0.0.0 < 3.5.22.40","control_rte_for_beckhoff_cx_sl >= 3.0.0.0 < 3.5.22.40","control_win_sl >= 3.0.0.0 < 3.5.22.40","runtime_toolkit >= 3.0.0.0 < 3.5.22.40","safety_sil2 >= 3.0.0.0 < 3.5.22.40","hmi_sl >= 3.0.0.0 < 3.5.22.40","development_system_3 >= 3.0.0.0 < 3.5.22.40","control_for_beaglebone_sl >= 3.5.0.0 < 4.23.0.0","control_for_empc-a_imx6_sl >= 3.5.0.0 < 4.23.0.0","control_for_iot2000_sl >= 3.5.0.0 < 4.23.0.0","control_for_linux_arm_sl >= 3.5.0.0 < 4.23.0.0","control_for_linux_sl >= 3.5.0.0 < 4.23.0.0","control_for_pfc100_sl >= 3.5.0.0 < 4.23.0.0","control_for_pfc200_sl >= 3.5.0.0 < 4.23.0.0","control_for_plcnext_sl >= 3.5.0.0 < 4.23.0.0","control_for_raspberry_pi_sl >= 3.5.0.0 < 4.23.0.0","control_for_wago_touch_panels_600_sl >= 3.5.0.0 < 4.23.0.0","virtual_control_sl >= 3.5.0.0 < 4.23.0.0"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T10:17:17.273","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79625","references":[{"url":"https://www.certvde.com/en/advisories/VDE-2026-097/","label":"info@cert.vde.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T10:01:20.476Z","slug":"CVE-2026-79625","body":"## Overview\n\nAffected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}