PatchSiren cyber security CVE debrief
CVE-2021-21865 Unknown Vendor CVE debrief
CVE-2021-21865 is an unsafe deserialization vulnerability in CODESYS PackageManagement.plugin ExtensionMethods.Clone() that can allow arbitrary command execution when a specially crafted file is processed. In the supplied advisory, the issue is tied to Festo Automation Suite deployments that include affected CODESYS components, and the reported severity is high (CVSS 7.8).
- Vendor
- Unknown Vendor
- Product
- FESTO
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-26
- Original CVE updated
- 2026-03-17
- Advisory published
- 2026-02-26
- Advisory updated
- 2026-03-17
Who should care
OT/ICS administrators, Festo Automation Suite operators, engineering workstations running CODESYS, and patch teams responsible for software distribution in industrial environments.
Technical summary
The advisory describes an unsafe deserialization flaw in PackageManagement.plugin ExtensionMethods.Clone() within CODESYS Development System 3.5.16. The CVSS vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates local access with user interaction is required, but successful exploitation could yield full confidentiality, integrity, and availability impact. The source advisory associates exposure with Festo Automation Suite deployments that include CODESYS, including setups below version 2.8.0.138 and configurations using CODESYS Development System 3.5.16.10.
Defensive priority
High. Treat as a priority patching issue for any affected Festo/CODESYS installation, especially on engineering or operator workstations that process untrusted files.
Recommended defensive actions
- Update Festo Automation Suite to version 2.8.0.138 or later, where CODESYS is no longer bundled with the suite.
- Install the latest patched CODESYS release directly from the official CODESYS website, following vendor installation guidance.
- Review any systems running CODESYS Development System 3.5.16.10 or related bundled components and remove or replace vulnerable versions.
- Restrict handling of untrusted or specially crafted files on engineering workstations until remediation is complete.
- Monitor Festo and CODESYS security advisories and apply updates promptly across the OT environment.
Evidence notes
This debrief is based on CISA CSAF advisory ICSA-26-076-01 (published 2026-02-26, republished 2026-03-17) and the supplied source item text. The advisory explicitly names the unsafe deserialization issue, the affected CODESYS component, the malicious-file trigger, and the remediation shift introduced in Festo Automation Suite 2.8.0.138. The supplied CVSS vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, supporting a high-severity, user-interaction-dependent local attack scenario. The prompt metadata marks the vendor identity as low-confidence/needs review, so product naming should be treated carefully and anchored to the advisory title and affected-product listings.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-21865 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-21865
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-21865 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-21865
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2025-108
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cve.org/CVERecord?id=CVE-2025-2595
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.