
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-12921 is a Use After Free (UAF) vulnerability in AzeoTech DAQFactory, an industrial HMI/SCADA data acquisition and control software. It affects DAQFactory versions 21.1 and prior, and can be exploited by an attacker using specially crafted .ctl files to achieve arbitrary code execution. The vulnerability was publicly disclosed on June 25, 2026, via a CISA ICS advisory (ICSA-26-169-02, Update A). It carries a CVSS v4.0 base score of 8.4 (High) and a CVSS v3.1 base score of 7.8 (High) (CISA Advisory, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), meaning DAQFactory references or operates on memory that has already been freed during the processing of .ctl project/control files. An attacker crafts a malicious .ctl file that triggers this memory mismanagement condition, causing the application to execute attacker-controlled code. Exploitation requires local access and active user interaction — specifically, a user must open or load the malicious .ctl file within the DAQFactory application. No privileges are required prior to exploitation. The vulnerability was reported to CISA by Rocco Calvi (@TecR0c) of TecSecurity and rgod of TrendAI Zero Day Initiative (CISA Advisory).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the DAQFactory application process, resulting in high impact to confidentiality, integrity, and availability of the vulnerable system. In industrial environments, this could lead to unauthorized manipulation of data acquisition processes, disruption of control system operations, or use of the compromised host as a pivot point within OT/ICS networks. The vulnerability does not affect subsequent/downstream systems directly per the CVSS v4.0 scoring, but the local code execution capability poses significant risk in critical manufacturing environments where DAQFactory is deployed (CISA Advisory, GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. CISA has confirmed that no known public exploitation specifically targeting this vulnerability has been reported. The EPSS score is approximately 0.14% (4th percentile), indicating a low near-term probability of exploitation. The vulnerability is not remotely exploitable and requires user interaction to open a malicious .ctl file, which limits its attack surface. No threat actor attribution has been identified, and the CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (CISA Advisory, GitHub Advisory).
.ctl file: Create a specially crafted AzeoTech DAQFactory .ctl project file that triggers a use-after-free condition during parsing or loading, causing the application to reference freed memory in a controlled manner..ctl file to a user operating DAQFactory version 21.1 or earlier on a Windows system..ctl file within the DAQFactory application (e.g., by disguising it as a legitimate project file)..ctl files placed in DAQFactory project directories, especially in locations writable by non-admin users; newly created executables or scripts in DAQFactory installation directories.cmd.exe, powershell.exe, wscript.exe); DAQFactory process crashing or restarting unexpectedly after loading a .ctl file..ctl file, particularly to uncommon destinations.A patch is available for versions after 21.1; users should update AzeoTech DAQFactory to the latest version beyond 21.1. CISA recommends the following interim mitigations: avoid opening .ctl files from unknown or untrusted sources; store .ctl files in folders writable only by administrator-level users; operate DAQFactory in "Safe Mode" when loading documents that have been outside of direct control; and apply a document editing password to project files. Additionally, isolate ICS/SCADA systems behind firewalls, avoid internet exposure, and use VPNs for any required remote access (CISA Advisory).
The vulnerability was disclosed via CISA's ICS advisory program (ICSA-26-169-02, Update A, published June 25, 2026), which is the primary official communication channel. The advisory was noted in automated CVE tracking feeds and aggregators including VulDB, CVEFeed, and Bluesky CVE notification accounts shortly after publication. No significant independent researcher commentary, vendor blog posts, or major media coverage beyond the CISA advisory has been identified at this time (CISA Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."