Darkreading Critical Vulnerability in TDengine Affects Industrial Systems
Article Content
- •CVE-2026-42542 allows unauthenticated remote crashes of TDengine servers.
- •The vulnerability affects numerous sectors, including industrial and IoT environments.
- •Organizations are urged to upgrade to TDengine version 3.4.1.6 and restrict access to port 6030.
A high-severity zero-day vulnerability, CVE-2026-42542, has been disclosed in TDengine, a time-series database widely used in industrial and IoT environments. This flaw allows unauthenticated attackers to crash affected servers with a single specially crafted network packet. The vulnerability affects TDengine versions 3.4.0.0 through 3.4.1.5, with a CVSS score of 7.5. Organizations using TDengine for critical operations, such as manufacturing and energy, are at risk, especially if the database is on a flat network. Although no exploitation in the wild has been confirmed, Ridge Security has developed a proof-of-concept exploit. TDengine has released a fixed version (3.4.1.6) and recommends organizations upgrade and restrict access to the default RPC port 6030. The vulnerability was discovered by Ridge Security during testing of open-source applications.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track McDonald's and CVE-2026-42542 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical RCE Vulnerability Discovered in TACACS+ Protocol A significant vulnerability has been identified in the TACACS+ protocol, allowing for pre-authentication remote code execution (RCE) attacks. This 33-year-old protocol, crucial for authentication in networking equipment, is widely used across large enterprises and ISPs. The vulnerability, detailed by Elttam, can be…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…