Skip to content
Critical Vulnerability in TDengine Affects Industrial Systems

Critical Vulnerability in TDengine Affects Industrial Systems

First seen 28 Sep 2026, 23:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 23:08 UTC
  • •CVE-2026-42542 allows unauthenticated remote crashes of TDengine servers.
  • •The vulnerability affects numerous sectors, including industrial and IoT environments.
  • •Organizations are urged to upgrade to TDengine version 3.4.1.6 and restrict access to port 6030.

A high-severity zero-day vulnerability, CVE-2026-42542, has been disclosed in TDengine, a time-series database widely used in industrial and IoT environments. This flaw allows unauthenticated attackers to crash affected servers with a single specially crafted network packet. The vulnerability affects TDengine versions 3.4.0.0 through 3.4.1.5, with a CVSS score of 7.5. Organizations using TDengine for critical operations, such as manufacturing and energy, are at risk, especially if the database is on a flat network. Although no exploitation in the wild has been confirmed, Ridge Security has developed a proof-of-concept exploit. TDengine has released a fixed version (3.4.1.6) and recommends organizations upgrade and restrict access to the default RPC port 6030. The vulnerability was discovered by Ridge Security during testing of open-source applications.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-10
CVE-2026-42542 published
Ridge Security disclosed a high-severity vulnerability in TDengine affecting versions 3.4.0.0 to 3.4.1.5.
Industrialcyber.Co
2026-09-25
Ridge Security warns of vulnerability
Ridge Security publicly disclosed the vulnerability's details, emphasizing its impact on operational technology.
Industrialcyber.Co
2026-09-28
Patch released for TDengine
TDengine released version 3.4.1.6 to address the vulnerability, urging users to upgrade.
Darkreading

More articles in this cluster (4)

Following this threat?

Track McDonald's and CVE-2026-42542 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed