Status: NEW | Advisory ID: CVE-2026-35227
| CVE | CVE-2026-35227 |
| CVSS Score / Version | 8.2 (High) / CVSS v4.0 |
| Updated | 2026-06-17 |
| Classified as | CWE-772 (Missing Release of Resource after Effective Lifetime) |
An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-35227 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-35227 |