CERT@VDE disclosed CVE-2026-8024, a critical deserialization flaw in iba's industrial data acquisition and automation products ibaPDA and ibaDatCoordinator that allows remote, unauthenticated code execution without user interaction. The bug is caused by unsafe use of the .NET BinaryFormatter to deserialize client-server input, a weakness tracked as CWE-502. The vulnerability carries critical severity ratings, including CVSS v3.1 9.8 and CVSS v4.0 9.3, and could let an attacker gain full system access or escalate privileges because malicious code may run under the affected service account.
Affected versions are ibaPDA before 8.14.0 and ibaDatCoordinator before 4.0.7, and patched releases are available. The issue was reported by Tenable researchers and coordinated through CERT@VDE, with no confirmed exploitation reported at publication time. Defenders are urged to apply vendor patches immediately and, if upgrades must be delayed, reduce exposure by restricting connections to localhost, tightening Windows Firewall rules, keeping the services off untrusted networks, and validating or otherwise preventing deserialization of untrusted data.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Patched versions were made available for the affected products, with ibaPDA fixed in version 8.14.0 and ibaDatCoordinator fixed in version 4.0.7. The references do not specify the exact release date of these patches.
Security Online states that Tenable researchers reported the unsafe .NET BinaryFormatter deserialization issue affecting ibaPDA and ibaDatCoordinator, and that CERT@VDE coordinated the disclosure process. The source does not provide a specific date for when the report was made.
CERT@VDE disclosed CVE-2026-8024 as a critical remote unauthenticated deserialization vulnerability in ibaPDA and ibaDatCoordinator. The flaw can allow arbitrary code execution and potential full system compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourcecertvde.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.