CVE-2026-102511: Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them
Apache PLC4X before 1.0.0 accepts spoofed ADS discovery responses that can redirect connections, CVE-2026-102511.
Apache disclosed CVE-2026-102511 in PLC4X, scored CVSS 4.0 8.5. ADS discovery accepts spoofed responses and derives the connection target from them, described as improper verification of the source of that data. Affected versions are the 0.10.0 and 0.11.0 lines before 1.0.0; Apache PLC4X 1.0.0 is unaffected. The oss-security note does not report exploitation in the wild.