HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Zero‑Day Remote Code Execution Vulnerability Discovered in PAX Technology Q80 Payment Terminals

A newly disclosed zero‑day (ZDI‑26‑525) in PAX Technology’s Q80 POS terminal allows unauthenticated remote code execution (CVSS 7.5). Retail and hospitality firms must map this flaw to SOC 2 controls and capture remediation evidence to stay audit‑ready.

LiveThreat™ Intelligence · 📅 August 06, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Zero‑Day Remote Code Execution Vulnerability Discovered in PAX Technology Q80 Payment Terminals

What Happened — A newly disclosed zero‑day (ZDI‑26‑525) in the PAX Technology Q80 AIP file parser enables a network‑adjacent attacker to execute arbitrary code without authentication. The advisory assigns a CVSS 7.5 (High) score.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the need for continuous control mapping: SOC 2 requires documented evidence that critical payment‑terminal configurations are tracked and that unpatched vulnerabilities are remediated promptly.
  • Highlights the importance of real‑time evidence collection for the “System Operations” and “Change Management” criteria (CC6.1, CC6.2) to prove that you are actively monitoring for exploitable flaws.
  • Provides a concrete audit artifact: the vulnerability advisory can be attached to your Trust Center evidence library to show due‑diligence during a SOC 2 audit.

Who Is Affected — Retail, hospitality, and any organization that deploys PAX Q80 (or similar point‑of‑sale) terminals for card‑present transactions.

Recommended Actions

  • Immediately inventory all Q80 devices and verify firmware version.
  • Apply any vendor‑released patches or mitigations; if none exist, isolate affected terminals from the network.
  • Map the vulnerability to SOC 2 control CC6.1 (System Operations) and CC6.2 (Change Management); capture remediation tickets, patch logs, and network‑segmentation evidence for audit review.
  • Enable continuous vulnerability scanning of payment‑terminal firmware and integrate findings into your compliance dashboard.

Source: Zero Day Initiative advisory ZDI‑26‑525

Technical Notes

  • Attack vector: Remote code execution via crafted AIP file parsing; requires only network proximity.
  • CVSS: 7.5 (High) – Network, No Authentication, Privilege Required: None, Impact: High.
  • Data at risk: Potential compromise of transaction data, POS configuration, and downstream systems if the attacker gains foothold.
📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-525/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →