VORANT. Threat Intelligence Sign in Get the full feed

Buffer Overflow Flaw Hits Pyramid NetStaX EtherNet/IP

routine vulnerability mediaenergy

A stack-based buffer overflow in Pyramid Solutions' NetStaX EtherNet/IP Stack could crash ICS devices or enable remote attacks; no active exploitation reported.

CISA published an ICS advisory for a vulnerability in Pyramid Solutions' NetStaX EtherNet/IP Stack, a communications library used in industrial control devices across critical manufacturing, energy, water/wastewater, and chemical sectors worldwide. The flaw, tracked as CVE-2026-78012, arises when a large Class 3 explicit-message request exceeds the application-side receive buffer without triggering an error or warning, potentially resulting in memory corruption, a device crash, or a remote attack vector where the originating device never receives a CIP error indicating the request failed.

The vulnerability affects all NetStaX EtherNet/IP Adapter and Scanner DLL/Development Kits (with and without CIP Security) prior to version 5.6.1. Pyramid Solutions responsibly disclosed the issue to CISA and has released v5.6.1, which adds a compile-time assertion, a runtime payload-size check, and improved documentation of packet/buffer-size relationships to close the gap. CISA notes no known public exploitation targeting this vulnerability at this time and recommends standard ICS network segmentation, minimizing internet exposure, and secure VPN use where remote access is required.

Defenders operating products built on the affected NetStaX kits should prioritize upgrading to v5.6.1 and verify vendor firmware/software updates from downstream OEMs that embed this stack. This is a vendor-disclosed vulnerability with a patch already available, not an actively exploited threat, making it routine advisory-driven patch management rather than an urgent incident-response matter.

Mentioned in this report

Vulnerabilities CVE-2026-78012

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free