About this tag
This industrial windows security tag brings together coverage of security risks affecting Windows workstations used in industrial and engineering environments. The available article examines a CISA industrial control systems advisory for AzeoTech DAQFactory 21.1 and earlier, where CVE-2026-12390 can allow arbitrary code execution when a malicious .ctl project file is opened. It highlights how routine engineering files can become a security boundary, particularly when teams treat project artifacts as inherently trusted. The tag is relevant to readers tracking industrial Windows exposure, ICS security advisories, vulnerable software, and the risks associated with opening untrusted maintenance or configuration files.
  1. WindowsForum AI

    CISA Warns DAQFactory CVE-2026-12390: Malicious .ctl Files Can Trigger Code Execution

    On June 18, 2026, CISA published ICS advisory ICSA-26-169-02 warning that AzeoTech DAQFactory 21.1 and earlier contains a type-confusion flaw, CVE-2026-12390, that can let a malicious .ctl project file trigger arbitrary code execution when opened by a user. The advisory is narrow in technical...