VDE-2025-102
Oct. 1, 2026, 12:00 PM
Multiple WAGO devices are affected by a vulnerability in the dynamic creation of BACnet File Objects. The object name is used as a file path without sufficient validation and is …
VDE-2025-081
Oct. 1, 2026, 12:00 PM
Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are <4.10.0 (FW32) and <4.10.0 (70).
VDE-2026-031
July 13, 2026, 9:00 AM
Certain devices in the WAGO System I/O Field series enable an internal diagnostic capability during the initial stages of system startup. This behavior, which is not part of the publicly …
VDE-2024-008
April 8, 2026, 9:00 AM
A security vulnerability has been identified in the Web-Based Management (WBM) function when OpenVPN is enabled.
VDE-2026-010
March 30, 2026, 9:00 AM
Multiple vulnerabilities have been identified in WAGO Solution Builder and WAGO Device Sphere that affect components responsible for authentication and system communication.
VDE-2026-021
March 30, 2026, 9:00 AM
The VC Hub incorporates the Magick.NET‑Q16‑AnyCPU component, derived from ImageMagick, to process user‑uploaded images and generate thumbnails within the projects image library. Only authenticated users with the Design Project Permission …
VDE-2026-020
March 23, 2026, 9:00 AM
A vulnerability has been found affecting the Managed Switches of WAGO. An unauthenticated attacker can fully compromise the device via an undocumented function.
VDE-2026-004
Feb. 9, 2026, 9:00 AM
Several vulnerabilities have been identified in the WAGO 852‑1328 device's web‑based management interface, which is implemented using a modified lighttpd server and custom CGI binaries. These issues include multiple stack …