← All Advisories

CODESYS Modbus TCP Server race condition in connection handling exhausts TCP connections and blocks legitimate clients

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-35227

Key Details

CVECVE-2026-35227
CVSS Score / Version8.2 (High) / CVSS v4.0
Updated2026-06-17
Classified asCWE-772 (Missing Release of Resource after Effective Lifetime)

What to Know

An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-35227
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-35227