CODESYS
CODESYS Modbus TCP Server Security Advisory
Pages
3
Time to read
3 mins
Publication
Language
English
Pages
3
Time to read
3 mins
Publication
Language
English
This document is a security advisory regarding the CODESYS Modbus TCP Server, identified as CODESYS Security Advisory 2026-05. It outlines a vulnerability related to improper resource management within the Modbus TCP server protocol stack. The flaw, associated with CVE-2026-35227, can lead to a situation where an unauthenticated remote attacker may exhaust all available TCP connections, thus preventing legitimate clients from establishing new connections. The advisory specifies that this issue affects all versions of CODESYS Modbus prior to 4.6.0.0. To remediate the vulnerability, users are advised to update to version 4.6.0.0 and ensure that the local Modbus TCP Server is also updated. Additionally, the document provides general security recommendations to enhance protection against such vulnerabilities, including the use of firewalls, encrypted communication links, and maintaining up-to-date virus detection solutions.