TDengine Patches Zero-Day Letting One Packet Crash OT Servers
Ridge Security disclosed CVE-2026-42542, a high-severity flaw in the open-source TDengine time-series database used across manufacturing, energy, automotive and IoT sectors. The bug lets an unauthenticated attacker crash a vulnerable server with a single crafted network packet; TDengine has released version 3.4.1.6 to fix versions 3.4.0.0 through 3.4.1.5.