---
id: CVE-2026-79625
title: >-
  Affected products do not properly synchronize access to their monitoring
  functionality
summary: >-
  Affected products do not properly synchronize access to their monitoring
  functionality. When multiple clients send concurrent requests, this may lead
  to incorrect reads or writes, or to corruption of internal memory structures.
  An authen…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-362
vendor: CODESYS
product: Control RTE (SL)
affected:
  - control_rte_sl >= 3.0.0.0 < 3.5.22.40
  - control_rte_for_beckhoff_cx_sl >= 3.0.0.0 < 3.5.22.40
  - control_win_sl >= 3.0.0.0 < 3.5.22.40
  - runtime_toolkit >= 3.0.0.0 < 3.5.22.40
  - safety_sil2 >= 3.0.0.0 < 3.5.22.40
  - hmi_sl >= 3.0.0.0 < 3.5.22.40
  - development_system_3 >= 3.0.0.0 < 3.5.22.40
  - control_for_beaglebone_sl >= 3.5.0.0 < 4.23.0.0
  - control_for_empc-a_imx6_sl >= 3.5.0.0 < 4.23.0.0
  - control_for_iot2000_sl >= 3.5.0.0 < 4.23.0.0
  - control_for_linux_arm_sl >= 3.5.0.0 < 4.23.0.0
  - control_for_linux_sl >= 3.5.0.0 < 4.23.0.0
  - control_for_pfc100_sl >= 3.5.0.0 < 4.23.0.0
  - control_for_pfc200_sl >= 3.5.0.0 < 4.23.0.0
  - control_for_plcnext_sl >= 3.5.0.0 < 4.23.0.0
  - control_for_raspberry_pi_sl >= 3.5.0.0 < 4.23.0.0
  - control_for_wago_touch_panels_600_sl >= 3.5.0.0 < 4.23.0.0
  - virtual_control_sl >= 3.5.0.0 < 4.23.0.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T10:17:17.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79625'
references:
  - url: 'https://www.certvde.com/en/advisories/VDE-2026-097/'
    label: info@cert.vde.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T10:01:20.476Z'
---

## Overview

Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
