PatchSiren cyber security CVE debrief
CVE-2026-12819 Delta Electronics CVE debrief
The Delta Electronics DVP12SE PLC is vulnerable due to an exposed Modbus TCP service without authentication or access control. This allows unauthorized read and write access to coils, holding registers, operational memory, relay states, and process control functions. The vulnerability affects operators of Delta Electronics DVP12SE PLC devices, industrial control system administrators, and cybersecurity teams responsible for protecting critical infrastructure. Evidence is based on CISA's CSAF advisory and CVE details. The affected product deployments should be reviewed for exposure, and defenders should verify the PLC configurations, network connectivity, and existing security controls. Additional information may be required to fully assess the vulnerability and implement effective mitigations. Operators of Delta Electronics DVP12SE PLC devices should prioritize applying vendor-recommended mitigations and compensating controls due to the critical severity and potential for unauthorized access. These stakeholders should review the PLC configurations, assess the vulnerability, and implement effective security measures to prevent exploitation. Additionally, they should consider the potential operational impact and develop strategies to minimize disruptions to industrial processes.
- Vendor
- Delta Electronics
- Product
- DVP12SE PLC
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-30
- Original CVE updated
- 2026-06-30
- Advisory published
- 2026-06-30
- Advisory updated
- 2026-06-30
Who should care
Operators of Delta Electronics DVP12SE PLC devices, industrial control system administrators, and cybersecurity teams responsible for protecting critical infrastructure should prioritize applying vendor-recommended mitigations and compensating controls due to the critical severity and potential for unauthorized access. These stakeholders should review the PLC configurations, assess the vulnerability, and implement effective security measures to prevent exploitation. Additionally, they should consider the potential operational impact and develop strategies to minimize disruptions to industrial processes.
Technical summary
The Delta Electronics DVP12SE PLC is vulnerable due to an exposed Modbus TCP service without authentication or access control. This allows unauthorized read and write access to coils, holding registers, operational memory, relay states, and process control functions. The vulnerability affects operators of Delta Electronics DVP12SE PLC devices, industrial control system administrators, and cybersecurity teams responsible for protecting critical infrastructure. The exposed service may allow attackers to manipulate PLC functions, potentially disrupting industrial processes.
Defensive priority
Operators of Delta Electronics DVP12SE PLC devices should prioritize applying vendor-recommended mitigations and compensating controls due to the critical severity and potential for unauthorized access.
Recommended defensive actions
- Enable IP Filter feature on DVP12SE PLC
- Set up PLC password protection
- Implement network isolation and firewall protection
- Restrict access to trusted IP addresses
- Refer to Delta Electronics' advisory page for updates
Evidence notes
The Delta Electronics DVP12SE PLC exposes a Modbus TCP service without authentication or access control, allowing unauthorized interaction with security-sensitive PLC functions. Evidence is based on CISA's CSAF advisory and CVE details. The affected product deployments should be reviewed for exposure, and defenders should verify the PLC configurations, network connectivity, and existing security controls. Additional information may be required to fully assess the vulnerability and implement effective mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12819 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12819
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12819 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12819
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-181-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.