PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12819 Delta Electronics CVE debrief

The Delta Electronics DVP12SE PLC is vulnerable due to an exposed Modbus TCP service without authentication or access control. This allows unauthorized read and write access to coils, holding registers, operational memory, relay states, and process control functions. The vulnerability affects operators of Delta Electronics DVP12SE PLC devices, industrial control system administrators, and cybersecurity teams responsible for protecting critical infrastructure. Evidence is based on CISA's CSAF advisory and CVE details. The affected product deployments should be reviewed for exposure, and defenders should verify the PLC configurations, network connectivity, and existing security controls. Additional information may be required to fully assess the vulnerability and implement effective mitigations. Operators of Delta Electronics DVP12SE PLC devices should prioritize applying vendor-recommended mitigations and compensating controls due to the critical severity and potential for unauthorized access. These stakeholders should review the PLC configurations, assess the vulnerability, and implement effective security measures to prevent exploitation. Additionally, they should consider the potential operational impact and develop strategies to minimize disruptions to industrial processes.

Vendor
Delta Electronics
Product
DVP12SE PLC
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-30
Original CVE updated
2026-06-30
Advisory published
2026-06-30
Advisory updated
2026-06-30

Who should care

Operators of Delta Electronics DVP12SE PLC devices, industrial control system administrators, and cybersecurity teams responsible for protecting critical infrastructure should prioritize applying vendor-recommended mitigations and compensating controls due to the critical severity and potential for unauthorized access. These stakeholders should review the PLC configurations, assess the vulnerability, and implement effective security measures to prevent exploitation. Additionally, they should consider the potential operational impact and develop strategies to minimize disruptions to industrial processes.

Technical summary

The Delta Electronics DVP12SE PLC is vulnerable due to an exposed Modbus TCP service without authentication or access control. This allows unauthorized read and write access to coils, holding registers, operational memory, relay states, and process control functions. The vulnerability affects operators of Delta Electronics DVP12SE PLC devices, industrial control system administrators, and cybersecurity teams responsible for protecting critical infrastructure. The exposed service may allow attackers to manipulate PLC functions, potentially disrupting industrial processes.

Defensive priority

Operators of Delta Electronics DVP12SE PLC devices should prioritize applying vendor-recommended mitigations and compensating controls due to the critical severity and potential for unauthorized access.

Recommended defensive actions

  • Enable IP Filter feature on DVP12SE PLC
  • Set up PLC password protection
  • Implement network isolation and firewall protection
  • Restrict access to trusted IP addresses
  • Refer to Delta Electronics' advisory page for updates

Evidence notes

The Delta Electronics DVP12SE PLC exposes a Modbus TCP service without authentication or access control, allowing unauthorized interaction with security-sensitive PLC functions. Evidence is based on CISA's CSAF advisory and CVE details. The affected product deployments should be reviewed for exposure, and defenders should verify the PLC configurations, network connectivity, and existing security controls. Additional information may be required to fully assess the vulnerability and implement effective mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12819 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12819

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12819 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12819

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-181-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.