PatchSiren cyber security CVE debrief
CVE-2026-3094 Unknown Vendor CVE debrief
CVE-2026-3094 affects Delta Electronics CNCSoft-G2 devices prior to V2.1.0.39. According to the CISA CSAF advisory ICSA-26-064-01, the issue is an out-of-bounds write in the DOPSoft component while parsing DPAX files, and Delta Electronics states the vulnerability is resolved in version V2.1.0.39. The advisory was published and last modified on 2026-03-05T07:00:00Z.
- Vendor
- Unknown Vendor
- Product
- Delta Electronics CNCSoft-G2 <V2.1.0.39
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-05
- Original CVE updated
- 2026-03-05
- Advisory published
- 2026-03-05
- Advisory updated
- 2026-03-05
Who should care
OT/ICS operators, engineers, and asset owners using Delta Electronics CNCSoft-G2 or the DOPSoft component should treat this as a priority. Security teams responsible for engineering workstations or systems that open or process DPAX files should also review exposure and patch status.
Technical summary
The advisory describes an out-of-bounds write condition in CNCSoft-G2's DOPSoft component during DPAX file parsing. Affected products are those prior to version V2.1.0.39. The vendor remediation states that updating to V2.1.0.39 resolves the issue. The source advisory also includes an SSVCv2 notation dated 2026-03-04T07:00:00Z, which is timing context from the advisory, not the publication date.
Defensive priority
High. The issue is rated CVSS 7.8 (HIGH) and affects software used in industrial/engineering workflows. Prioritize version verification and patching, then apply interim handling controls for DPAX files until affected systems are updated.
Recommended defensive actions
- Inventory all Delta Electronics CNCSoft-G2 installations and confirm whether any are earlier than V2.1.0.39.
- Apply the vendor update to V2.1.0.39 from the Delta Electronics download center.
- Until systems are updated, restrict or closely review handling of DPAX files, especially untrusted files.
- Test the update in a controlled environment before rolling it into production OT or engineering systems.
- Review CISA industrial control system recommended practices for general defense-in-depth measures.
Evidence notes
This debrief is based on the supplied CISA CSAF source item for ICSA-26-064-01 and the linked Delta Electronics remediation notice. The source text explicitly states that Delta Electronics CNCSoft-G2 devices prior to V2.1.0.39 are vulnerable to an out-of-bounds write while parsing DPAX files in the DOPSoft component, and that V2.1.0.39 resolves the vulnerability. The source advisory metadata lists publication and modification on 2026-03-05T07:00:00Z.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-3094 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-3094
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-3094 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3094
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-064-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-064-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.