Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2025-102
Oct. 1, 2026, 12:00 PM
Multiple WAGO devices are affected by a vulnerability in the dynamic creation of BACnet File Objects. The object name is used as a file path without sufficient validation and is …
VDE-2025-081
Oct. 1, 2026, 12:00 PM
Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are <4.10.0 (FW32) and <4.10.0 (70).
VDE-2026-097
Sept. 30, 2026, 12:00 PM
The monitoring functionality of affected CODESYS Control runtime systems processes read and write requests to PLC application data sent by the CODESYS Development System and other clients such as HMIs. …
VDE-2026-094
Sept. 30, 2026, 12:00 PM
The CODESYS Gateway Client (CmpGatewayClient) is used by various CODESYS products to establish PLC communication via the CODESYS Gateway. Due to missing limits on memory allocations derived from a size …
VDE-2026-089
Sept. 21, 2026, 6:00 PM
The Lenze VPN client is vulnerable to a Remote Code Execution. The vulnerability would allow an attacker to perform a remote code execution on the computer running the client with …
VDE-2026-014
Sept. 16, 2026, 10:00 AM
The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and …
VDE-2026-027
Sept. 16, 2026, 10:00 AM
The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerabilities that can be used to bypass authentication. Code can be executed on …
VDE-2026-028
Sept. 16, 2026, 10:00 AM
The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and …