Upgrade to NetStaX v5.6.1 or later. For systems where immediate upgrade is not possible, CISA recommends: minimizing network exposure for control system devices, ensuring devices are not internet-accessible, locating control system networks behind firewalls and isolating them from business networks, and using VPNs updated to the most current version when remote access is required. Perform proper impact analysis and risk assessment prior to deploying defensive measures.
Quick answers
What is CVE-2026-78012?
Upgrade to NetStaX v5.6.1 or later. For systems where immediate upgrade is not possible, CISA recommends: minimizing network exposure for control system devices, ensuring devices are not internet-accessible, locating control system networks behind firewalls and isolating them from business networks, and using VPNs updated to the most current version when remote access is required. Perform proper impact analysis and risk assessment prior to deploying defensive measures.
How severe is CVE-2026-78012?
critical, CVSS 9.8
Is CVE-2026-78012 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-78012 be mitigated?
Upgrade to NetStaX v5.6.1 or later. For systems where immediate upgrade is not possible, CISA recommends: minimizing network exposure for control system devices, ensuring devices are not internet-accessible, locating control system networks behind firewalls and isolating them from business networks, and using VPNs updated to the most current version when remote access is required. Perform proper impact analysis and risk assessment prior to deploying defensive measures.
CVSS
9.8
Vendor
Pyramid Solutions
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
EtherNet/IP Adapter DLL Kit (EIPA), EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE), EtherNet/IP Adapter Development Kit (EADK), EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE), EtherNet/IP Scanner DLL Kit (EIPS), EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE), EtherNet/IP Scanner Development Kit (ESDK), EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE)
Mitigation
Upgrade to NetStaX v5.6.1 or later. For systems where immediate upgrade is not possible, CISA recommends: minimizing network exposure for control system devices, ensuring devices are not internet-accessible, locating control system networks behind firewalls and isolating them from business networks, and using VPNs updated to the most current version when remote access is required. Perform proper impact analysis and risk assessment prior to deploying defensive measures.
A stack-based buffer overflow vulnerability (CVE-2026-78012) in Pyramid Solutions NetStaX EtherNet/IP Stack versions prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. Successful exploitation may result in memory corruption, device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating the request could not be processed. The vulnerability affects Adapter and Scanner kits in both DLL and Development Kit formats, including Secure variants. Pyramid Solutions has released NetStaX v5.6.1 with mitigations including compile-time assertions and runtime payload-size checks. CISA has added the vulnerability to its ICS advisories, noting worldwide deployment across critical infrastructure sectors.