CVE-2026-35227: Codesys Modbus

High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.

An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.

Affected products

  • Codesys Codesys Modbus: from 1.0.0.0, before 4.6.0.0 (fixed in 4.6.0.0)

Published 2026-05-12. Last modified 2026-06-17.