This document is a security advisory detailing a vulnerability in the CODESYS Control runtime system's CmpAuditLog component. The advisory outlines that the vulnerability, identified as CVE-2026-3509, allows potentially unauthenticated remote attackers to control the format string of processed log messages, which may lead to a denial-of-service (DoS) condition on affected PLCs. The advisory specifies the affected products and their respective versions, recommending updates to mitigate the issue. It also provides mitigation strategies, including disabling the Audit Log feature in the runtime configuration file. Additionally, the advisory includes general security recommendations for protecting controllers and devices, emphasizing the importance of a secure environment, user management, and encrypted communication. The document concludes with acknowledgments and a disclaimer regarding liability and the availability of features in different territories.