Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-8024 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-8024 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-8024 is a critical deserialization of untrusted data vulnerability affecting ibaPDA and ibaDatCoordinator, industrial data acquisition and coordination software products developed by iba AG, exploitable remotely without authentication.

Technical Detail

The flaw resides in the deserialization handling within ibaPDA and ibaDatCoordinator, where the application processes attacker-supplied serialized data without adequate validation or integrity checks. A remote, unauthenticated attacker can send crafted serialized payloads to the affected service, triggering arbitrary code execution in the context of the application process. Successful exploitation grants full system access, which in industrial environments may include the ability to manipulate data acquisition processes, disrupt operations, or pivot to connected OT network segments.

Exploitation Status

No known exploit code has been publicly observed or confirmed as of June 25, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Despite the absence of a known exploit, the critical CVSS score of 9.8 and the unauthenticated remote attack vector make this a high-priority candidate for exploitation development, particularly given the industrial software context.

Who Is Targeting This

No confirmed threat actor attribution is available at this time. Reported (research-inferred): No specific named actors have been publicly linked to this vulnerability. Attribution data carries medium confidence and no origin or motivation has been established. No campaigns involving this CVE have been identified.

What To Do

Organizations running ibaPDA or ibaDatCoordinator should apply vendor-supplied patches from iba AG immediately, prioritizing internet-facing or network-accessible deployments. Until patching is complete, restrict network access to affected services using firewall rules or network segmentation, ensuring these components are not reachable from untrusted networks or the public internet. Where possible, place ibaPDA and ibaDatCoordinator behind a dedicated OT network zone with strict ingress filtering. Monitor application and network logs for anomalous deserialization activity or unexpected outbound connections from affected hosts. Given the critical severity and unauthenticated attack surface, treat this as a patch-now priority regardless of current exploitation status.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →