CVE-2026-12921
AzeoTech DAQFactory vulnerability analysis and mitigation

Overview

CVE-2026-12921 is a Use After Free (UAF) vulnerability in AzeoTech DAQFactory, an industrial HMI/SCADA data acquisition and control software. It affects DAQFactory versions 21.1 and prior, and can be exploited by an attacker using specially crafted .ctl files to achieve arbitrary code execution. The vulnerability was publicly disclosed on June 25, 2026, via a CISA ICS advisory (ICSA-26-169-02, Update A). It carries a CVSS v4.0 base score of 8.4 (High) and a CVSS v3.1 base score of 7.8 (High) (CISA Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), meaning DAQFactory references or operates on memory that has already been freed during the processing of .ctl project/control files. An attacker crafts a malicious .ctl file that triggers this memory mismanagement condition, causing the application to execute attacker-controlled code. Exploitation requires local access and active user interaction — specifically, a user must open or load the malicious .ctl file within the DAQFactory application. No privileges are required prior to exploitation. The vulnerability was reported to CISA by Rocco Calvi (@TecR0c) of TecSecurity and rgod of TrendAI Zero Day Initiative (CISA Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the DAQFactory application process, resulting in high impact to confidentiality, integrity, and availability of the vulnerable system. In industrial environments, this could lead to unauthorized manipulation of data acquisition processes, disruption of control system operations, or use of the compromised host as a pivot point within OT/ICS networks. The vulnerability does not affect subsequent/downstream systems directly per the CVSS v4.0 scoring, but the local code execution capability poses significant risk in critical manufacturing environments where DAQFactory is deployed (CISA Advisory, GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. CISA has confirmed that no known public exploitation specifically targeting this vulnerability has been reported. The EPSS score is approximately 0.14% (4th percentile), indicating a low near-term probability of exploitation. The vulnerability is not remotely exploitable and requires user interaction to open a malicious .ctl file, which limits its attack surface. No threat actor attribution has been identified, and the CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (CISA Advisory, GitHub Advisory).

Exploitation steps

  1. Craft malicious .ctl file: Create a specially crafted AzeoTech DAQFactory .ctl project file that triggers a use-after-free condition during parsing or loading, causing the application to reference freed memory in a controlled manner.
  2. Deliver the file to the target: Use social engineering, phishing, shared network drives, or supply chain compromise to deliver the malicious .ctl file to a user operating DAQFactory version 21.1 or earlier on a Windows system.
  3. Induce user interaction: Convince the target user to open the malicious .ctl file within the DAQFactory application (e.g., by disguising it as a legitimate project file).
  4. Trigger UAF and achieve code execution: When DAQFactory processes the crafted file, the use-after-free condition is triggered, allowing the attacker to redirect execution flow to attacker-controlled code running with the privileges of the DAQFactory process (CISA Advisory).

Indicators of compromise

  • File System: Unexpected or unsigned .ctl files placed in DAQFactory project directories, especially in locations writable by non-admin users; newly created executables or scripts in DAQFactory installation directories.
  • Process: Unusual child processes spawned by the DAQFactory process (e.g., cmd.exe, powershell.exe, wscript.exe); DAQFactory process crashing or restarting unexpectedly after loading a .ctl file.
  • Logs: Windows Event Logs showing application crashes (Event ID 1000/1001) associated with the DAQFactory process; unexpected process creation events logged by EDR solutions originating from the DAQFactory parent process.
  • Network: Unexpected outbound network connections from the DAQFactory host to external IPs following the loading of a .ctl file, particularly to uncommon destinations.

Mitigation and workarounds

A patch is available for versions after 21.1; users should update AzeoTech DAQFactory to the latest version beyond 21.1. CISA recommends the following interim mitigations: avoid opening .ctl files from unknown or untrusted sources; store .ctl files in folders writable only by administrator-level users; operate DAQFactory in "Safe Mode" when loading documents that have been outside of direct control; and apply a document editing password to project files. Additionally, isolate ICS/SCADA systems behind firewalls, avoid internet exposure, and use VPNs for any required remote access (CISA Advisory).

Community reactions

The vulnerability was disclosed via CISA's ICS advisory program (ICSA-26-169-02, Update A, published June 25, 2026), which is the primary official communication channel. The advisory was noted in automated CVE tracking feeds and aggregators including VulDB, CVEFeed, and Bluesky CVE notification accounts shortly after publication. No significant independent researcher commentary, vendor blog posts, or major media coverage beyond the CISA advisory has been identified at this time (CISA Advisory).

Additional resources


SourceThis report was generated using AI

Related AzeoTech DAQFactory vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12921HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoNoJun 25, 2026
CVE-2026-12390HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoNoJun 18, 2026
CVE-2025-66590HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoYesDec 11, 2025
CVE-2025-66589HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoYesDec 11, 2025
CVE-2025-66588HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoYesDec 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management