Critical severity9.8NVD Advisory· Published Jun 26, 2026· Updated Jul 6, 2026
CVE-2026-28701
CVE-2026-28701
Description
Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.
Affected products
4- cpe:2.3:o:daktronics:vfc-dmp-5000_firmware:*:*:*:*:*:*:*:*Range: <8.117.0.0
Patches
Vulnerability mechanics
References
2- github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-04.jsonnvdThird Party Advisory
- www.cisa.gov/news-events/ics-advisories/icsa-26-176-04nvdThird Party AdvisoryUS Government Resource
News mentions
2- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News · Jul 6, 2026
- Daktronics Controller FirmwareCISA ICS Advisories