CVE-2026-12390
AzeoTech DAQFactory vulnerability analysis and mitigation

Overview

CVE-2026-12390 is a Type Confusion vulnerability in AzeoTech DAQFactory versions 21.1 and prior that allows attackers to execute arbitrary code via specially crafted .ctl files. The vulnerability was disclosed on June 18, 2026, with CISA publishing ICS Advisory ICSA-26-169-02, later updated on June 25, 2026. It affects DAQFactory deployments worldwide, particularly in critical manufacturing sectors. The vulnerability carries a CVSS v4.0 base score of 8.4 (High) and a CVSS v3.1 base score of 7.8 (High) (CISA Advisory, Github Advisory).

Technical details

The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type / 'Type Confusion'), where DAQFactory allocates or initializes a resource using one type but later accesses it using an incompatible type during .ctl file parsing. Exploitation requires local access and active user interaction — a victim must open a maliciously crafted .ctl file — but requires no privileges or special attack conditions. The attack vector is local (AV:L), with low complexity and no authentication required, meaning an attacker who can deliver a malicious .ctl file to a target user can trigger code execution upon file load. The vulnerability was reported by Rocco Calvi (@TecR0c) of TecSecurity and rgod of TrendAI Zero Day Initiative (CISA Advisory).

Impact

Successful exploitation results in arbitrary code execution on the affected DAQFactory system, with high impact to confidentiality, integrity, and availability of the vulnerable system. An attacker could gain full control of the DAQFactory host, potentially accessing sensitive industrial process data, modifying control configurations, or disrupting operations in critical manufacturing environments. Because DAQFactory is an industrial HMI/SCADA platform, compromise could have downstream effects on connected operational technology (OT) assets and physical processes (CISA Advisory, Github Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and CISA has confirmed no known public exploitation specifically targeting this vulnerability at the time of disclosure. The vulnerability is not remotely exploitable — it requires local file delivery and user interaction to open a malicious .ctl file. The EPSS score is approximately 0.148% (4th percentile), indicating a low near-term probability of exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (CISA Advisory, Github Advisory).

Exploitation steps

  1. Craft malicious .ctl file: Create a specially crafted AzeoTech DAQFactory .ctl project file that triggers a type confusion condition during parsing, causing the application to access a memory resource using an incompatible type.
  2. Deliver the file to the target: Use social engineering, phishing, a shared network drive, or supply chain compromise to deliver the malicious .ctl file to a user operating DAQFactory version 21.1 or earlier.
  3. Induce user to open the file: Convince the target user to open the malicious .ctl file within DAQFactory (e.g., by disguising it as a legitimate project file).
  4. Trigger type confusion: Upon loading, DAQFactory processes the malformed file, triggering the type confusion vulnerability in the file parsing logic.
  5. Achieve code execution: The type confusion condition leads to memory corruption or misuse, resulting in arbitrary code execution in the context of the DAQFactory process on the victim's system (CISA Advisory).

Indicators of compromise

  • File System: Unexpected or unknown .ctl files present in DAQFactory project directories, especially those received via email or external sources; new executables or scripts created in DAQFactory installation directories.
  • Process: Unusual child processes spawned by the DAQFactory process (e.g., cmd.exe, powershell.exe, wscript.exe); DAQFactory process exhibiting unexpected network connections.
  • Logs: Application crash logs or error events in Windows Event Viewer associated with DAQFactory at the time of .ctl file loading; access violation or memory corruption entries in DAQFactory logs.
  • Network: Outbound connections from the DAQFactory host to unknown external IP addresses following .ctl file load events.

Mitigation and workarounds

No patched version number has been explicitly specified beyond "a version after 21.1" — users should upgrade AzeoTech DAQFactory to the latest available version beyond 21.1. CISA recommends the following interim mitigations: avoid opening .ctl files from unknown or untrusted sources; store .ctl files in folders writable only by admin-level users; operate DAQFactory in "Safe Mode" when loading documents outside of direct control; and apply a document editing password to project files. Additionally, isolate DAQFactory systems behind firewalls, restrict internet exposure, and use VPNs for any required remote access (CISA Advisory).

Community reactions

CISA published ICS Advisory ICSA-26-169-02 on June 18, 2026, and updated it on June 25, 2026 to add a related CVE (CVE-2026-12921) and update advisory wording. The vulnerability was picked up by automated CVE tracking feeds and security news aggregators shortly after disclosure, with no notable independent researcher commentary or significant social media discussion identified beyond standard CVE notification channels (CISA Advisory).

Additional resources


SourceThis report was generated using AI

Related AzeoTech DAQFactory vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12921HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoNoJun 25, 2026
CVE-2026-12390HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoNoJun 18, 2026
CVE-2025-66590HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoYesDec 11, 2025
CVE-2025-66589HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoYesDec 11, 2025
CVE-2025-66588HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoYesDec 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management