CVE-2025-41659 – CODESYS Control RTE and Runtime Toolkit

CVSS 8.3 HIGH

“Industrial control systems fail hard when trust boundaries break.”

This CODESYS patch addresses multiple vulnerabilities across Control RTE (SL) and the Runtime Toolkit, directly impacting industrial automation environments. CVE-2025-41660 and CVE-2025-41659 are high-severity issues that can compromise system integrity and disrupt operational control, posing risk to both availability and safety in ICS deployments. CVE-2025-41658 introduces a medium-severity weakness that contributes to the overall exposure of the runtime environment.

CVE-2025-41660 has a CVSS score of 8.8, which is High severity. CVE-2025-41659 has a CVSS score of 8.3, which is High severity. CVE-2025-41658 has a CVSS score of 5.5, which is Medium severity. There is no verified evidence of active exploitation or publicly available proof-of-concept code for these vulnerabilities.

Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.