CVE-2019-16871: Beckhoff Twincat
Critical severity, CVSS 9.8. EPSS: 5.3% chance of exploitation in the next 30 days.
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
Affected products
- Beckhoff Twincat: from 3.0, before 3.1 (fixed in 3.1); version 2.0 only; version 3.1 only
Published 2019-12-19. Last modified 2026-06-17.