CVE-2026-9158: Eclipse 4diac Forte

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).

Affected products

  • Eclipse 4diac Forte: from 3.0.0, up to and including 3.1.0

Published 2026-06-18. Last modified 2026-07-02.