All stories
criticalExploited VulnerabilitiesCVE-2026-12819CVE-2026-12818

Critical Vulnerabilities Expose Delta Electronics DVP-12SE PLCs to Unauthorized Access

Delta Electronics' DVP-12SE PLCs have been exposed to critical vulnerabilities (CVE-2026-12818 and CVE-2026-12819) due to a lack of authentication in their Modbus TCP service, leading to unauthorized access and resource allocation issues. The high CVSS score of 9.3 indicates severe risk, urging immediate mitigation actions from affected organizations.

Summary

Delta Electronics has disclosed two critical vulnerabilities affecting its DVP-12SE Programmable Logic Controllers (PLCs). These vulnerabilities stem from a Modbus TCP service that lacks authentication or access control, allowing unauthenticated users to interact with security-sensitive functions. The first vulnerability (CVE-2026-12818) involves resource allocation without limits or throttling, while the second (CVE-2026-12819) permits unauthorized interaction with PLC functions. Both vulnerabilities have a CVSS score of 9.3, highlighting their critical nature and potential impact on industrial control systems.

What happened

Delta Electronics' DVP-12SE PLCs are vulnerable due to exposed Modbus TCP services that lack necessary security measures such as authentication or access controls. This oversight allows attackers to interact with the PLC's functions without any form of verification, posing a significant risk to operational integrity and safety. The vulnerabilities were identified as CVE-2026-12818 and CVE-2026-12819, both carrying a CVSS score of 9.3.

Technical details

The technical breakdown reveals two distinct issues within the DVP-12SE PLCs:

  1. CVE-2026-12818: This vulnerability is related to resource allocation without limits or throttling (CWE-770). It allows attackers to exploit the system by overloading it with requests, potentially leading to denial of service conditions.

  2. CVE-2026-12819: This vulnerability permits unauthenticated interaction with security-sensitive PLC functions due to a lack of authentication and access control mechanisms. This could lead to unauthorized command execution or data manipulation within the PLC environment.

Both vulnerabilities are critical due to their potential impact on industrial operations, emphasizing the need for immediate remediation.

Affected products and fixed versions

The affected product is the Delta Electronics DVP-12SE PLC. As of now, specific patched versions have not been disclosed in the available sources. Organizations using this product should monitor official communications from Delta Electronics for updates on patches or mitigations.

Exploitation status

While there is no explicit mention of active exploitation in the provided sources, the critical nature of these vulnerabilities suggests a high risk of potential exploitation. Organizations are advised to take proactive measures to secure their systems against possible attacks.

Indicators of compromise

No specific indicators of compromise (IOCs) have been identified in the available documentation. However, organizations should monitor for unusual network traffic patterns or unauthorized access attempts related to Modbus TCP services as part of their detection strategy.

Detection opportunities

Organizations can enhance their detection capabilities by monitoring network traffic for unexpected interactions with Modbus TCP ports associated with DVP-12SE PLCs. Implementing network segmentation and access controls can also help in identifying and mitigating potential threats.

Timeline

The vulnerabilities were officially disclosed on June 30, 2026, through a Delta Electronics security advisory. The advisory provides detailed information about the vulnerabilities and their implications, urging affected organizations to take immediate action.

Why this matters for defenders

For defenders, these vulnerabilities underscore the importance of securing industrial control systems against unauthorized access. The lack of authentication in Modbus TCP services can lead to severe operational disruptions and safety hazards. Organizations must prioritize patching and implementing robust security measures to protect their critical infrastructure from potential exploitation.

What remains unclear

The sources do not provide information on specific patched versions or detailed remediation steps beyond monitoring for advisories from Delta Electronics. Additionally, there is no confirmation of active exploitation, leaving organizations to assess the risk based on the severity of the vulnerabilities.

Defender guidance

Defenders should take the following actions:

  • Monitor Advisories: Stay updated with official communications from Delta Electronics regarding patches or mitigations.
  • Network Monitoring: Implement network monitoring for unusual traffic patterns related to Modbus TCP services.
  • Access Controls: Enforce strict access controls and authentication mechanisms on all industrial control systems.
  • Segmentation: Use network segmentation to isolate critical systems and limit potential attack vectors.

By taking these steps, organizations can mitigate the risks posed by CVE-2026-12818 and CVE-2026-12819 and protect their operational integrity.

Sources

  1. https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-07
  2. https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00011_DVP12SE%20Multiple%20Vulnerabilities%20(CVE-2026-12818,%20CVE-2026-12819)_v1.0.pdf
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -