CVE-2026-12390Disclosure(azeotech / daqfactory)

MEDIUMCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch azeotech daqfactory systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • daqfactory

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-06-18); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
daqfactory

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-18: 3Mentions · 2026-06-19: 1Active Exploitation · 2026-06-19: 1Patch / Workaround · 2026-06-18: 1Technical Details · 2026-06-18: 3Technical Details · 2026-06-19: 106-1806-19
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-183
Disclosure3
2026-06-191
Active Exploitation1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-12390 In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in … https://www.cve.org/CVERecord?id=CVE-2026-12390

    Post summary

    A type‑confusion vulnerability (CVE‑2026‑12390) in AzeoTech DAQFactory 21.1 and earlier can be triggered by specially crafted .ctl files, as noted in the CVE record.

    01000230
    57.6K followersView on X
  • Alpaca@Alpaca744
    Disclosure

    CVE-2026-12390: AzeoTech DAQFactory (<=21.1) lets a crafted .ctl file run arbitrary code via type confusion. CVSS 8.4. The only "fix" CISA lists is mitigations, no patch. Be honest: how many ICS shops actually password-protect their .ctl docs?

    Post summary

    The post announces CVE‑2026‑12390 in AzeoTech DAQFactory, a type‑confusion flaw allowing arbitrary code execution via crafted .ctl files, with a CVSS score of 8.4, and notes that only mitigations are provided by CISA, with no patch available.

    1000069
    64 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers are exploiting CVE-2026-12390 in AzeoTech DAQFactory through malicious .ctl files to achieve arbitrary code execution. TRC analysis shows subsequent lateral movement across industrial networks highlights the need for runtime segmentation to contain post-compromise activity. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/icsa-26-169-02-cve-2026-12390

    Post summary

    The tweet reports real‑world exploitation of CVE‑2026‑12390 in AzeoTech DAQFactory through malicious .ctl files that allows arbitrary code execution and lateral movement, underscoring the need for runtime segmentation.

    0000042
    1.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12390 In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in … https://www.cve.org/CVERecord?id=CVE-2026-12390 ----- Traducción: CVE-2026-12390 En … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑12390, a Type Confusion flaw in AzeoTech DAQFactory 21.1 and earlier, exploitable via crafted .ctl files, but provides no PoC, exploit, or patch info.

    0000036
    82 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appazeotechdaqfactory---

Explore more