TL;DR

A critical remote code execution vulnerability (CVE-2026-0975) exists in Delta Electronics DIAView, allowing attackers to execute arbitrary commands if a user opens and runs malicious content.

What happened

['Remote attacker can execute arbitrary code on affected systems']

Why it matters for ops

['User interaction with malicious project required', 'High severity allows for significant system compromise']

Mitigation

  • Update DIAView to the latest version
  • Disable unnecessary features and services
  • Monitor for suspicious activities

Action items

  • Patch affected systems immediately
  • Review project access controls
  • Implement network segmentation

Detection IOCs

  • Unexpected network traffic to/from DIAView instances
  • Unauthorized changes in file permissions or content related to DIAView projects

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-049/