Junglewise Threat Intelligence

CVE-2026-12576: Delta Electronics DVP80ES3 improper message integrity enforcement

CVE-2026-12576 · Severity: high · CVSS 7.5 · Published 2026-07-01

Technologies: Delta Electronics DVP80ES3. Vendors: Delta Electronics.

Executive brief

Delta Electronics DVP80ES3 series programmable logic controllers (PLCs), which are used to automate industrial machinery and processes, are vulnerable to a communication flaw. An attacker can exploit this issue to disrupt the device's operations, potentially leading to a complete loss of availability for the industrial equipment it controls. This could result in production downtime or the inability to manage critical infrastructure remotely.

Technical details

The Delta Electronics DVP80ES3 PLC firmware (up to version 1.06.00) contains a vulnerability classified as CWE-924, involving the improper enforcement of message integrity during transmission. This flaw exists within the communication channel used by the device. A remote, unauthenticated attacker can exploit this weakness over the network without any user interaction. Successful exploitation primarily impacts the availability of the device, potentially allowing an attacker to cause a denial-of-service (DoS) condition. Users are advised to refer to Delta Electronics advisory Delta-PCSA-2026-00009 for remediation steps.

Affected products

  • Delta Electronics DVP80ES3 <= 1.06.00

Timeline

  • 2026-07-01: advisory: Initial publication of CVE-2026-12576 by Delta Electronics and NVD.

References

Related threats