
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-12390 is a Type Confusion vulnerability in AzeoTech DAQFactory versions 21.1 and prior that allows attackers to execute arbitrary code via specially crafted .ctl files. The vulnerability was disclosed on June 18, 2026, with CISA publishing ICS Advisory ICSA-26-169-02, later updated on June 25, 2026. It affects DAQFactory deployments worldwide, particularly in critical manufacturing sectors. The vulnerability carries a CVSS v4.0 base score of 8.4 (High) and a CVSS v3.1 base score of 7.8 (High) (CISA Advisory, Github Advisory).
The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type / 'Type Confusion'), where DAQFactory allocates or initializes a resource using one type but later accesses it using an incompatible type during .ctl file parsing. Exploitation requires local access and active user interaction — a victim must open a maliciously crafted .ctl file — but requires no privileges or special attack conditions. The attack vector is local (AV:L), with low complexity and no authentication required, meaning an attacker who can deliver a malicious .ctl file to a target user can trigger code execution upon file load. The vulnerability was reported by Rocco Calvi (@TecR0c) of TecSecurity and rgod of TrendAI Zero Day Initiative (CISA Advisory).
Successful exploitation results in arbitrary code execution on the affected DAQFactory system, with high impact to confidentiality, integrity, and availability of the vulnerable system. An attacker could gain full control of the DAQFactory host, potentially accessing sensitive industrial process data, modifying control configurations, or disrupting operations in critical manufacturing environments. Because DAQFactory is an industrial HMI/SCADA platform, compromise could have downstream effects on connected operational technology (OT) assets and physical processes (CISA Advisory, Github Advisory).
No public proof-of-concept exploit code is known to exist, and CISA has confirmed no known public exploitation specifically targeting this vulnerability at the time of disclosure. The vulnerability is not remotely exploitable — it requires local file delivery and user interaction to open a malicious .ctl file. The EPSS score is approximately 0.148% (4th percentile), indicating a low near-term probability of exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (CISA Advisory, Github Advisory).
.ctl file: Create a specially crafted AzeoTech DAQFactory .ctl project file that triggers a type confusion condition during parsing, causing the application to access a memory resource using an incompatible type..ctl file to a user operating DAQFactory version 21.1 or earlier..ctl file within DAQFactory (e.g., by disguising it as a legitimate project file)..ctl files present in DAQFactory project directories, especially those received via email or external sources; new executables or scripts created in DAQFactory installation directories.cmd.exe, powershell.exe, wscript.exe); DAQFactory process exhibiting unexpected network connections..ctl file loading; access violation or memory corruption entries in DAQFactory logs..ctl file load events.No patched version number has been explicitly specified beyond "a version after 21.1" — users should upgrade AzeoTech DAQFactory to the latest available version beyond 21.1. CISA recommends the following interim mitigations: avoid opening .ctl files from unknown or untrusted sources; store .ctl files in folders writable only by admin-level users; operate DAQFactory in "Safe Mode" when loading documents outside of direct control; and apply a document editing password to project files. Additionally, isolate DAQFactory systems behind firewalls, restrict internet exposure, and use VPNs for any required remote access (CISA Advisory).
CISA published ICS Advisory ICSA-26-169-02 on June 18, 2026, and updated it on June 25, 2026 to add a related CVE (CVE-2026-12921) and update advisory wording. The vulnerability was picked up by automated CVE tracking feeds and security news aggregators shortly after disclosure, with no notable independent researcher commentary or significant social media discussion identified beyond standard CVE notification channels (CISA Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."