Industrial Control Systems at Risk as Zero-Day Vulnerability Exposes Thousands of Servers
A high-severity zero-day vulnerability has been discovered in an open-source database used across various industrial sectors, putting thousands of servers at risk of crashing with a single malicious packet. The flaw affects TDengine, a time-series database widely adopted by organizations in manufacturing, energy, automotive, and IoT environments.
TDengine’s database is responsible for storing and analyzing vast amounts of data collected over time, including sensor readings and equipment performance metrics. With over 730,000 instances running across multiple industry sectors, including Siemens, McDonald’s, Sinopec, and NavInfo, the potential impact of this vulnerability is significant. The affected organizations use TDengine to monitor and control their operations, making a denial-of-service (DoS) condition particularly detrimental.
Researchers from Ridge Security discovered the flaw while testing open-source applications used in IoT and operational technology (OT) environments that often fall outside traditional IT security tools’ scope. According to Ridge Security, the vulnerability is an “ordinary failure” in an important place – the database’s pre-authentication message parsing code. This is where the integer-underflow bug occurs, allowing attackers to bypass security checks and crash vulnerable servers with a single specially crafted packet.
The zero-day vulnerability, tracked as CVE-2026-42542, affects TDengine versions 3.4.0.0 through 3.4.1.5 and has been fixed in version 3.4.1.6. Despite the lack of evidence suggesting any attacks have targeted this flaw in the wild, Ridge Security emphasizes that exploit code could become public at any time. The security vendor itself has developed a proof-of-concept exploit but chose not to disclose it publicly.
In an interview with Dark Reading, Ridge Security researcher Yan Zhou noted that exploiting CVE-2026-42542 is relatively straightforward for an attacker with network access to port 6030. “The vulnerability can be triggered with a single malformed network packet, without requiring credentials or an established session,” Zhou explained. This ease of exploitation makes the risk particularly concerning in industrial environments where downtime can have severe consequences.
To mitigate this threat, organizations using TDengine are advised to upgrade to the fixed version and restrict access to TCP port 6030, the database’s default RPC port. As Ridge Security emphasized, preventing a DoS condition is essential in maintaining visibility into equipment and operations, which is critical for industrial environments.
In conclusion, the discovery of CVE-2026-42542 serves as a reminder that even seemingly ordinary security flaws can have significant consequences when exploited in critical environments. Organizations relying on TDengine must prioritize patching and access controls to prevent potential crashes and maintain business continuity.
Source: Dark Reading — 2026-09-28