HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

CVE-2026-12390: AzeoTech DAQFactory CTL File Parsing Type Confusion RCE Vulnerability

AzeoTech’s DAQFactory software contains a type‑confusion flaw (CVE‑2026‑12390) that lets remote attackers execute code after a victim opens a malicious file or page. The vulnerability scores 7.8 (CVSS) and requires a patch. For SOC 2‑aligned organizations, unpatched industrial‑control software can breach change‑management and system‑operation controls, jeopardizing audit readiness.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

CVE-2026-12390: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability

What It Is — A type‑confusion flaw in the CTL file parser of AzeoTech’s DAQFactory lets a remote attacker execute arbitrary code when a victim opens a crafted file or visits a malicious web page.

Exploitability — User interaction is required; a proof‑of‑concept has been demonstrated. The vulnerability carries a CVSS 7.8 (High) score (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Affected Products — AzeoTech DAQFactory (all versions prior to the July 2026 security update).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 – Risk Management: Organizations must identify, assess, and remediate vulnerabilities in a documented, timely manner. An unpatched RCE flaw directly violates this control.
  • SOC 2 CC7.1 – System Operations: Production systems must run approved, patched software; evidence of patch deployment is required for auditability.
  • Continuous Monitoring: Demonstrating ongoing scanning for vulnerable third‑party components provides the audit trail enterprise buyers now demand for SOC 2‑aligned contracts.

Recommended Actions

  • Inventory all DAQFactory installations across your environment.
  • Patch each instance with AzeoTech’s July 2026 update immediately.
  • Document the remediation in your vulnerability‑management system and map it to SOC 2 CC6.1 and CC7.1 controls.
  • Enable continuous scanning for unpatched DAQFactory versions to retain evidence for future audits.

Source: Zero Day Initiative Advisory (ZDI‑26‑449)

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-449/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →