All stories
highExploited VulnerabilitiesCVE-2026-12390

High-Severity Code Execution Flaw in AzeoTech DAQFactory Compromises Multiple Versions

AzeoTech's DAQFactory has been compromised through a high-severity Type Confusion vulnerability (CVE-2026-12390), allowing attackers to execute code via specially crafted .ctl files. Versions 21.1 and earlier are affected, with no current KEV status from CISA. Immediate patching is advised for all users of these versions.

Summary

AzeoTech's DAQFactory software has been targeted by a Type Confusion vulnerability (CVE-2026-12390), which poses a significant risk to systems running version 21.1 and earlier. This flaw allows attackers to execute arbitrary code by exploiting .ctl files, leading to potential unauthorized access and control over affected systems. Despite the high CVSS score of 8.4, this vulnerability has not yet been listed in CISA's Known Exploited Vulnerabilities (KEV) database.

What Happened

The vulnerability stems from improper handling of .ctl files within DAQFactory, which can be manipulated to trigger a Type Confusion error. This error allows attackers to execute code with the same privileges as the application, potentially leading to full system compromise. The issue affects all versions up to and including 21.1, making it crucial for users to verify their software version immediately.

Affected Products and Fixed Versions

The vulnerability specifically impacts DAQFactory versions 21.1 and earlier. Users of these versions are at risk until they apply the necessary patches or updates provided by AzeoTech. The company has not yet released a specific patch, but upgrading to a newer version is recommended as a temporary mitigation measure.

Exploitation Status

As of now, there have been no confirmed reports of this vulnerability being exploited in the wild. However, given its high CVSS score and the potential for severe impact, organizations using affected versions should consider it an active threat until further notice. The absence of this vulnerability from CISA's KEV database does not diminish its risk.

Defender Guidance

Organizations must prioritize patching or upgrading their DAQFactory installations to mitigate this vulnerability. Users should:

  • Verify the version of DAQFactory they are running.
  • Immediately contact AzeoTech for guidance on available patches or updates.
  • Consider temporary network segmentation or access restrictions for systems running vulnerable versions.

By taking these steps, organizations can significantly reduce the risk posed by CVE-2026-12390 until a permanent fix is deployed.

Sources

  1. https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-02
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -