CVE-2026-3630Disclosure(deltaww / commgr2)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch deltaww commgr2 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • commgr2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 14 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 13 signals
  • Disclosure: 9 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 7 mentions (2026-03-09); latest day: 1
  • 14 total mentions across 7 days

Affected systems

Vendors
Products
commgr2

Deep dive

Activity timeline14 mentions / 7d
02457Mentions · 2026-03-09: 7Mentions · 2026-03-10: 2Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-03-17: 1Mentions · 2026-03-19: 1Mentions · 2026-04-01: 1Active Exploitation · 2026-04-01: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-09: 6Technical Details · 2026-03-10: 2Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-19: 1Technical Details · 2026-04-01: 103-0903-1003-1203-1303-1703-1904-01
Signal classification4 categories
Disclosure
964.3%
General
214.3%
Patch
214.3%
Active Exploitation
17.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-097
Disclosure5General2
2026-03-102
Disclosure1Patch1
2026-03-121
Disclosure1
2026-03-131
Disclosure1
2026-03-171
Patch1
2026-03-191
Disclosure1
2026-04-011
Active Exploitation1
Full discourse14 posts
  • Praetorian@praetorianlabs
    Disclosure

    🚨 CVE-2026-3630 — CVSS 9.8 critical RCE in Delta Electronics COMMGR2. No auth required, network-accessible. Full breakdown 👇 https://buff.ly/QmIGLWe #OffensiveSecurity #VulnerabilityResearch #NetworkSecurity #Praetorian

    Post summary

    The tweet announces a new, high‑severity RCE vulnerability (CVE‑2026‑3630) in Delta Electronics COMMGR2, providing basic technical details but no evidence of exploitation or mitigation.

    01012216
    8.6K followersView on X
  • Praetorian@praetorianlabs
    Patch

    🚨 CVE-2026-3630: Critical buffer overflow in Delta COMMGR2 (CVSS 9.8) • Unauthenticated RCE • No user interaction needed • Targets industrial automation • Patch available Industrial orgs assess exposure now. #CVE20263630 #IndustrialSecurity https://www.praetorian.com/?p=10723

    Post summary

    CVE-2026-3630 is a critical buffer overflow vulnerability in Delta COMMGR2 that allows unauthenticated remote code execution on industrial automation systems (CVSS 9.8), and a patch is available; industrial organizations should assess exposure immediately.

    01021356
    8.6K followersView on X
  • B4K3D・゚✧@0xB4K3D
    General

    64-byte buffer + strcpy = eternal pwn. No bounds check → >64 bytes overflows → smash return addr → hijack to shellcode. Defenses got better, but IoT/firmware/kernels still full of C bugs. CVE-2026-3630 (Delta industrial RCE), Zephyr RTOS 9.4 CVSS overflow, Tenda routers stacking overflows...

    Post summary

    A brief note pointing out buffer overflow details for CVE-2026-3630 and other related C bugs, but lacking PoC, exploit, or patch information.

    00011104
    961 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-3630 to compromise Delta Electronics COMMGR2 systems, then escalating privileges and moving laterally across industrial networks. Runtime segmentation helps contain post-compromise activity in critical infrastructure environments. #Vulnerability 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/delta-electronics-2026-commgr2-buffer-overflow

    Post summary

    The report confirms that CVE-2026-3630 is actively exploited against Delta Electronics COMMGR2 systems via a buffer overflow, with attackers escalating privileges and moving laterally, yet no patch or PoC details are shared.

    0000042
    1.9K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3630 (CVSS:9.8, CRITICAL) is Analyzed. Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability...https://nvd.nist.gov/vuln/detail/CVE-2026-3630 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE‑2026‑3630 is a critical stack‑based buffer overflow in Delta Electronics COMMGR2, as reported by the NVD.

    0000033
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3630 (CVSS:9.8, CRITICAL) is Analyzed. Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability...https://nvd.nist.gov/vuln/detail/CVE-2026-3630 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical stack-based buffer overflow vulnerability (CVE-2026-3630) affecting Delta Electronics' COMMGR2, providing basic technical details and an NVD link but no PoC, exploit, or patch information.

    0000027
    172 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3630 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3630 #CVE-2026-3630 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/wB4nlMRl9m

    Post summary

    The tweet announces CVE-2026-3630 as a critical vulnerability with a 9.8 CVSS score, but offers no evidence of exploits, patches, or false positives.

    0000021
    92 followersView on X
  • maru@maru1151157
    Patch

    🚨 CVE-2026-3630 (CVSS: 9.8) Delta Electronics COMMGR2のスタックベースバッファオーバーフロー脆弱性。悪意のあるパケット送信でリモートコード実行可能。パッチ適用と入力検証で対策。 https://maruomosquit.com/vulnerability/CVE-2026-3630/ #脆弱性 #セキュリティ

    Post summary

    An identified stack‑based buffer overflow (CVE‑2026‑3630) in Delta Electronics COMMGR2 allows remote code execution; a vendor patch and input‑validation mitigations are now available.

    0000093
    1.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3630 Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability. https://www.cve.org/CVERecord?id=CVE-2026-3630 ----- Traducción: CVE-2026-3630 Delta Electronics COMMGR2 tiene una vulnerabilidad de desbordamiento de búfer basada en pila. … http://infoflow.cloud`

    Post summary

    A new stack‑based buffer overflow CVE‑2026‑3630 has been disclosed for Delta Electronics COMMGR2; no PoC, exploit, patch, or active exploitation information is provided.

    0000029
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3630 Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability. https://www.cve.org/CVERecord?id=CVE-2026-3630

    Post summary

    The statement announces a stack‑based buffer overflow in Delta Electronics COMMGR2 (CVE‑2026‑3630) with a link to its CVE record, but provides no additional exploitation details or mitigation information.

    00000145
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-3630 - Critical Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability. https://www.thehackerwire.com/vulnerability/CVE-2026-3630/ https://t.co/bvzgeReL1h

    Post summary

    The tweet announces CVE-2026-3630, a critical stack-based buffer overflow vulnerability in Delta Electronics COMMGR2, and links to a source for additional details.

    0000046
    130 followersView on X
  • VulDB 🛡@vuldb
    General

    A new vulnerability with increased severity was disclosed for Delta Electronics COMMGR2 (CVE-2026-3630) https://vuldb.com/?id.349787

    Post summary

    Delta Electronics COMMGR2 vulnerability (CVE-2026-3630) was disclosed with increased severity, but no additional technical or operational details are provided.

    0000077
    2.1K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3630: CRITICAL] Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability.#cve,CVE-2026-3630,#cybersecurity https://cvefind.com/CVE-2026-3630

    Post summary

    Delta Electronics' COMMGR2 product is disclosed to have a critical stack‑based buffer overflow (CVE‑2026‑3630) without any reference to exploits or mitigation.

    0000064
    600 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-3630: Stack-based Buffer Overflow Vulne... Remote stack smashing in Delta's COMMGR2 with zero auth required - industrial networks just became sitting ducks for RCE... https://zerodaysignal.com/vulnerability/CVE-2026-3630 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-3630, a stack-based buffer overflow in Delta's COMMGR2 that allows unauthenticated remote code execution.

    00000120
    140 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdeltawwcommgr2---

Explore more