PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3094 Unknown Vendor CVE debrief

CVE-2026-3094 affects Delta Electronics CNCSoft-G2 devices prior to V2.1.0.39. According to the CISA CSAF advisory ICSA-26-064-01, the issue is an out-of-bounds write in the DOPSoft component while parsing DPAX files, and Delta Electronics states the vulnerability is resolved in version V2.1.0.39. The advisory was published and last modified on 2026-03-05T07:00:00Z.

Vendor
Unknown Vendor
Product
Delta Electronics CNCSoft-G2 <V2.1.0.39
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-05
Original CVE updated
2026-03-05
Advisory published
2026-03-05
Advisory updated
2026-03-05

Who should care

OT/ICS operators, engineers, and asset owners using Delta Electronics CNCSoft-G2 or the DOPSoft component should treat this as a priority. Security teams responsible for engineering workstations or systems that open or process DPAX files should also review exposure and patch status.

Technical summary

The advisory describes an out-of-bounds write condition in CNCSoft-G2's DOPSoft component during DPAX file parsing. Affected products are those prior to version V2.1.0.39. The vendor remediation states that updating to V2.1.0.39 resolves the issue. The source advisory also includes an SSVCv2 notation dated 2026-03-04T07:00:00Z, which is timing context from the advisory, not the publication date.

Defensive priority

High. The issue is rated CVSS 7.8 (HIGH) and affects software used in industrial/engineering workflows. Prioritize version verification and patching, then apply interim handling controls for DPAX files until affected systems are updated.

Recommended defensive actions

  • Inventory all Delta Electronics CNCSoft-G2 installations and confirm whether any are earlier than V2.1.0.39.
  • Apply the vendor update to V2.1.0.39 from the Delta Electronics download center.
  • Until systems are updated, restrict or closely review handling of DPAX files, especially untrusted files.
  • Test the update in a controlled environment before rolling it into production OT or engineering systems.
  • Review CISA industrial control system recommended practices for general defense-in-depth measures.

Evidence notes

This debrief is based on the supplied CISA CSAF source item for ICSA-26-064-01 and the linked Delta Electronics remediation notice. The source text explicitly states that Delta Electronics CNCSoft-G2 devices prior to V2.1.0.39 are vulnerable to an out-of-bounds write while parsing DPAX files in the DOPSoft component, and that V2.1.0.39 resolves the vulnerability. The source advisory metadata lists publication and modification on 2026-03-05T07:00:00Z.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-3094 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-3094

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-3094 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3094

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-064-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-064-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.