logo

Attackers Chain Flaws to Backdoor CODESYS Applications and Deploy Malicious Code

ID: 7aa9fdb1-4341-50b6-b7aa-d107ea404152

STIX ID: report--7aa9fdb1-4341-50b6-b7aa-d107ea404152

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-04-27

Date Updated: 2026-05-05

Author: AnuPriya

...
...

Nozomi Networks Labs disclosed three critical vulnerabilities in the CODESYS Control runtime that can be chained by a low-privileged authenticated attacker to extract credentials and cryptographic keys, modify PLC application backups (ZIP with weak CRC32), and restore backdoored applications that execute as root after reboot; CODESYS issued patches and mandatory code signing, and organizations are urged to patch, harden credentials, segment OT, and monitor for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.