CISA flags two critical Delta DVP12SE PLC flaws
For exposed control networks, this is the bill coming due for treating operational technology segmentation as a future project.
TL;DR
The Cybersecurity and Infrastructure Security Agency (CISA) issued a June 30 advisory for all Delta Electronics DVP12SE programmable logic controller (PLC) versions, disclosing CVE-2026-12819 and CVE-2026-12818. Successful exploitation could allow remote commands, control-logic changes and resource exhaustion over Modbus TCP without authentication. CISA lists Common Vulnerability Scoring System (CVSS) 3.1 scores of 9.8 and CVSS 4.0 scores of 9.3 for both flaws. Contractors, state chief information security officers and municipal IT teams running these PLCs in manufacturing or infrastructure systems get no patch yet, only Delta's IP filtering, password protection, isolation, firewall and virtual private network workarounds.
The Cybersecurity and Infrastructure Security Agency's initial advisory is short, and the operational message is not: any Delta Electronics DVP12SE programmable logic controller reachable on Modbus TCP is a control-system risk until the owner proves otherwise. CVE-2026-12819 exposes the Modbus TCP service without authentication or access control, allowing an unauthenticated network source to read and write coils, holding registers, operational memory, relay states and process control functions. CVE-2026-12818 lets a remote attacker flood TCP/502 with raw or malformed packets because the service lacks resource limits or throttling. CISA lists all versions as affected, places the equipment in Critical Manufacturing, and gives each vulnerability a Common Vulnerability Scoring System (CVSS) 3.1 score of 9.8 and CVSS 4.0 score of 9.3.
The remediation column is where the advisory turns into an asset-owner problem. Delta is aware of the flaws and is working on a fix, but CISA's advisory gives no patch date. Delta's workarounds are the controls that should already be ordinary in a mature operational technology (OT) environment: enable the PLC's IP Filter feature, restrict access to trusted human-machine interface (HMI) panels or supervisory control and data acquisition (SCADA) hosts, set PLC password protection, place the device on an independent OT control network behind a firewall, keep it off the office network and the internet, and use an updated, authorized virtual private network for remote access. That buys time. It does not fix the controller.
For contractors, state chief information security officers and municipal IT teams, Monday's work is inventory, reachability and compensating-control evidence. Find DVP12SE devices, confirm whether TCP/502 is reachable outside the OT enclave, restrict allowed IPs to named HMI or SCADA hosts, test whether password protection actually blocks logic download and overwrite, and document the residual risk if the controller cannot be retired. CISA says it has no reports of public exploitation specifically targeting these vulnerabilities. That fact helps triage. It does nothing for a PLC reachable from untrusted networks. This is the attack surface industrial control system owners have been warned about for years. The CVE number is new. The segmentation failure, where it exists, has been sitting there.
Published ·Deep Fathom