High severity7.8NVD Advisory· Published Jun 25, 2026· Updated Jul 16, 2026
CVE-2026-12921
CVE-2026-12921
Description
In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.
Affected products
2cpe:2.3:a:azeotech:daqfactory:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:azeotech:daqfactory:*:*:*:*:*:*:*:*range: <=21.1
- (no CPE)range: <=21.1
Patches
Vulnerability mechanics
References
1- www.cisa.gov/news-events/ics-advisories/icsa-26-169-02nvdThird Party AdvisoryUS Government Resource
News mentions
2- ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution VulnerabilityZero Day Initiative · Jul 23, 2026
- AzeoTech DAQFactory (Update A)CISA ICS Advisories