CVE-2026-12390: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability
What It Is — A type‑confusion flaw in the CTL file parser of AzeoTech’s DAQFactory lets a remote attacker execute arbitrary code when a victim opens a crafted file or visits a malicious web page.
Exploitability — User interaction is required; a proof‑of‑concept has been demonstrated. The vulnerability carries a CVSS 7.8 (High) score (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Affected Products — AzeoTech DAQFactory (all versions prior to the July 2026 security update).
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 – Risk Management: Organizations must identify, assess, and remediate vulnerabilities in a documented, timely manner. An unpatched RCE flaw directly violates this control.
- SOC 2 CC7.1 – System Operations: Production systems must run approved, patched software; evidence of patch deployment is required for auditability.
- Continuous Monitoring: Demonstrating ongoing scanning for vulnerable third‑party components provides the audit trail enterprise buyers now demand for SOC 2‑aligned contracts.
Recommended Actions
- Inventory all DAQFactory installations across your environment.
- Patch each instance with AzeoTech’s July 2026 update immediately.
- Document the remediation in your vulnerability‑management system and map it to SOC 2 CC6.1 and CC7.1 controls.
- Enable continuous scanning for unpatched DAQFactory versions to retain evidence for future audits.