Executive Overview
Delta Electronics, in coordination with the Cybersecurity and Infrastructure Security Agency (CISA), has disclosed a critical memory corruption vulnerability designated CVE-2026-74810 affecting its CNC HMI and CNC Soft software suites. Rated with a CVSS v3.1 base score of 9.4 (Critical), the flaw enables unauthenticated network adversaries on the factory shop-floor subnet to overwrite execution memory, achieving arbitrary code execution or subtly altering active Computer Numerical Control (CNC) machining program files.
Delta Electronics CNC controllers drive 5-axis vertical machining centers (VMCs), CNC lathes, and automated laser cutters worldwide. These systems manufacture high-tolerance mechanical assemblies for civil aviation turbine blades, aerospace structural airframes, defense ordnance, and precision medical implants.
Vulnerability Dissection: Network G-Code Parser Buffer Overflow
Delta CNC HMI includes an integrated communication service listening on TCP port 8088 used by CAD/CAM software to remotely stream NC programs and monitor spindle telemetry. When the daemon receives a crafted NC block containing extended macro parameters (such as custom G-code or M-code subroutines), an unchecked buffer copy allows arbitrary byte overwrite past the allocated program memory buffer:
// Vulnerable snippet in Delta CNC G-code parser
void process_remote_nc_block(const char *block_data, size_t block_len) {
char active_gcode_line[128];
// VULNERABLE: Unbounded string copy allows overwrite of spindle speed registers and feed-rate variables
strcpy(active_gcode_line, block_data);
execute_nc_interpreter(active_gcode_line);
}
Physical Safety & Quality Sabotage Impact
Unlike standard IT malware that seeks data theft, exploiting machine tool controllers introduces severe physical sabotage hazards reminiscent of the historic Stuxnet incident:
- Subtle Dimensional Sabotage: By subtly altering toolpath coordinate offsets (e.g., shifting coordinate axes by 50 microns), an attacker can introduce invisible structural micro-fractures in aerospace components that pass initial visual inspection but fail catastrophically under operational stress.
- Physical Spindle Crash: Overriding rapid traverse rates (G00) or commanding the tool changer to engage the spindle during high-speed rotation causes explosive tool breakage, damaging multi-million dollar machining centers.
- Operator Physical Hazard: Overriding door interlock safety signals while high-pressure coolant and 24,000 RPM spindles are active poses acute physical danger to machine operators.
Remediation & Shop-Floor Defense-in-Depth
Industrial manufacturing plants operating Delta CNC equipment must implement the following protective measures:
- Apply Software Patches: Upgrade Delta CNC HMI to version
3.4.1or higher as instructed in Delta Advisory DE-2026-004. - Isolate CNC Subnets (Purdue Level 1/2): Place all machine tools and CNC workstations on dedicated manufacturing VLANs with no direct connectivity to corporate IT or guest Wi-Fi.
- Implement Physical Key Lockouts: Enable the physical program lock key on the CNC operator console, preventing remote network updates to NC memory without an operator physically inserting and turning the key.
- Post-Process Verification: Enforce offline cryptographic hash verification on all NC program files transferred to machine tools via air-gapped USB media or dedicated secure DNC servers.



