CVE-2025-41700: Codesys

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.

Affected products

  • Codesys Codesys: before 3.5.21.40 (fixed in 3.5.21.40)

Published 2025-12-01. Last modified 2026-06-17.