Critical Buffer Overflow Vulnerability Affects Pyramid Solutions NetStaX EtherNet/IP Stack
CVE-2026-78012 allows silent memory corruption via oversized Class 3 explicit messages
Key Takeaways
- CVE-2026-78012 is a critical stack-based buffer overflow in Pyramid Solutions NetStaX EtherNet/IP Stack affecting versions prior to v5.6.1.
- The vulnerability allows oversized Class 3 explicit-message requests to exceed the application-side receive buffer without generating an error or warning.
- Successful exploitation could lead to memory corruption, device crashes, or remote attack vectors without CIP error indication.
- Affected products span Adapter and Scanner kits in DLL and Development Kit formats, including Secure variants.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


