High severity7.8NVD Advisory· Published Mar 4, 2026· Updated Jun 17, 2026
CVE-2026-3094
CVE-2026-3094
Description
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Affected products
3cpe:2.3:a:deltaww:cncsoft-g2:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:deltaww:cncsoft-g2:*:*:*:*:*:*:*:*range: <2.1.0.39
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
1News mentions
1- ZDI-26-151: Delta Electronics CNCSoft-G2 DPAX File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityZero Day Initiative · Mar 6, 2026