#TDengine
-New malware: Psychedelic Stealer, BotHelper RAT, Carbonato botnet, PavokwiLoader, Sauron, Corp MDM Android spyware, RemControl and RedWing Android banking trojans
-New Roundcube bug exploited in the wild
-TrustSink technique
-TDengine vulnerability impacts IoT and ICS devices
September 25, 2026 at 8:08 AM
🎄 Jour 3 du Calendrier de l'Avent des 🐻

TDengine : Une base de données temps réel optimisée pour l’IoT et l’IA
December 3, 2025 at 8:26 PM
TDengine, IIoT için tasarlanmış, yüksek performanslı, ölçeklenebilir zaman serisi veritabanıdır. Milyarlarca sensör verisini işler, yüksek kardinalite sorununa çözüm sunar.

github.com/taosdata/TDe...

#IIoT #ZamanSerisi #Veritabanı
GitHub - taosdata/TDengine: High-performance, scalable time-series database designed for Industrial IoT (IIoT) scenarios
High-performance, scalable time-series database designed for Industrial IoT (IIoT) scenarios - taosdata/TDengine
github.com
September 23, 2026 at 5:10 AM
New OT zero-day can take down a database with one packet, and you may not know it’s there 

Ridge researchers discovered CVE-2026-42542, a high-severity vulnerability in TDengine, a time-series database used in industrial IoT, manufacturing, energy, connected vehicles and other environments that…
New OT zero-day can take down a database with one packet, and you may not know it’s there 
Ridge researchers discovered CVE-2026-42542, a high-severity vulnerability in TDengine, a time-series database used in industrial IoT, manufacturing, energy, connected vehicles and other environments that rely on machine and sensor data. The basic problem is pretty striking: an unauthenticated attacker can crash a TDengine server with a single malformed packet. No credentials, session or user interaction are required. Ridge has not yet observed exploitation or identified any attack IOCs – however, AI-aided vulnerability discovery and chaining have substantially changed the security equation, and the pace of exploitation is only expected to increase.
itnerd.blog
September 24, 2026 at 7:58 PM
The first MySQL release of DataCollie is almost ready. Looking forward, I’ve reprioritized the roadmap:
Support for emerging databases such as Milvus, TDengine, and StarRocks will come before traditional databases — to fill the tooling gap in these fast-growing ecosystems.
#buildinpublic #indiedev
June 14, 2025 at 4:54 PM
🚀 Just published: TDengine — High-performance time-series database for industrial data

Purpose-built database for Industry 4.0 and IoT that enables real-time ingestion, storage, and analysis of massive sensor data with high compression

https://openalternative.co/tdengine
June 9, 2025 at 10:00 PM
DockerボットネットがAIキーを探索。BragJack攻撃がブラウザAIアシスタントを標的に。TDengineの脆弱性が産業テレメトリの停止を脅かす。
In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
ShinyHunters seizes Clop’s leak site, CARBONATO botnet hunts AI keys on Docker hosts, and infostealer exposure in the US water sector.
www.securityweek.com
September 25, 2026 at 5:08 PM
Breaking down bugs in TDengine to master refactoring, part 1: sausage code
pvs-studio.com/en/blog/post...
Breaking down bugs in TDengine to master refactoring, part 1: sausage code
The analysis of the TDengine project code using PVS-Studio reveals classic errors and typos. Developers could′ve avoided many of them if they had carefully designed the code in the first place, kept.....
pvs-studio.com
March 6, 2025 at 4:03 AM
Breaking down bugs in TDengine to master refactoring, part 2: stack-consuming macro
pvs-studio.com/en/blog/post...
Breaking down bugs in TDengine to master refactoring, part 2: stack-consuming macro
Get ready for code smells, classic errors, and typos when checking the TDengine project using PVS-Studio. Much of this is avoidable if we design code carefully from the beginning, keep the logic...
pvs-studio.com
March 19, 2025 at 8:14 PM
Breaking down bugs in TDengine to master refactoring, part 3: price of laziness
pvs-studio.com/en/blog/post...
Breaking down bugs in TDengine to master refactoring, part 3: price of laziness
Get ready for code smells, classic errors, and typos when checking the TDengine project using PVS-Studio. Developers could′ve prevented many of them if they had carefully designed the code in the...
pvs-studio.com
April 1, 2025 at 3:41 PM
Curious about what else is hiding in the codebase? Read the full article covering other bugs in the project:

pvs-studio.com/en/blog/post...
Why SSDLC needs static analysis: a case study of 190 bugs in TDengine
Static code analysis is one of the most important components of secure software development. It detects errors and potential vulnerabilities early in the development process, when they′re cheaper and....
pvs-studio.com
August 7, 2026 at 12:45 PM
#cpp
PVS-Studio team checked the codebase of #TDengine, an open-source database for IoT systems, and spotted a buffer overflow that only strikes on #64-bit systems:
August 7, 2026 at 12:45 PM
What’s the best database for IoT in 2026?

The answer has changed. Modern IoT workloads need more than fast ingestion. They need SQL analytics, open storage formats, and infrastructure that scales without locking up the data.

We broke down what to look for here:

basekick.net/blog/best-da...
The Best Database for IoT in 2026: An Honest Comparison | Basekick Labs
Choosing an IoT database in 2026: MQTT ingestion paths, edge constraints, cardinality, and retention. InfluxDB 3, TimescaleDB, VictoriaMetrics, GreptimeDB, ClickHouse, IoTDB, TDengine, SQLite, and Arc...
basekick.net
August 3, 2026 at 3:45 PM
💫 25,000 GitHub stars and counting! TDengine keeps growing! Shoutout to the team 🔥

Time-series database and historian for industrial data

openalternative.co/tdengine
July 26, 2026 at 6:06 PM
CVE-2026-62351 - Critical OOB read in TDengine. Unauthenticated crash via malformed RPC packets. CVSS 7.5. Patch to 3.4.1.15 immediately. #CVE #TDengine #infosec

https://www.valtersit.com/cve/CVE-2026-62351/
July 16, 2026 at 12:11 PM
CVE-2026-62355 - TDengine: Standard User permission unexpect
CVE ID : CVE-2026-62355

Published : July 15, 2026, 7:18 p.m. | 15 minutes ago

Description : TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data R...
CVE-2026-62355 - TDengine: Standard User permission unexpect
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could run create udf even though standard users should have read-only permissions for non-database objects and show dnodes and create user were denied. This …
cvefeed.io
July 15, 2026 at 9:00 PM
CVE-2026-62350 - TDengine: UDF lead to RCE
CVE ID : CVE-2026-62350

Published : July 15, 2026, 7:18 p.m. | 15 minutes ago

Description : TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf pri...
CVE-2026-62350 - TDengine: UDF lead to RCE
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could upload a crafted shared library and install it as a user-defined function, such as eval, then execute arbitrary C code on the TDengine server side through database …
cvefeed.io
July 15, 2026 at 8:40 PM
CVE-2026-62348 - TDengine: KILL SSMIGRATE missing authorization lets low-privilege users interrupt shared-storage migrations
CVE ID : CVE-2026-62348

Published : July 15, 2026, 7:18 p.m. | 15 minutes ago

Description : TDengine is a time-series database optimized for Inter...
CVE-2026-62348 - TDengine: KILL SSMIGRATE missing authorization lets low-privilege users interrupt shared-storage migrations
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-privilege SQL user to run KILL SSMIGRATE against an active shared-storage migration because mndProcessKillSsMigrateReq called mndKillSsMigrate while the intended MND_OPER_SSMIGRATE_DB privilege check was commented out. This issue is fixed in …
cvefeed.io
July 15, 2026 at 8:38 PM
🚨 EUVD-2026-44769
📊 5.4/10
🏢 taosdata

📝 TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-privileg...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44769

#cybersecurity #infosec #cve #euvd
July 15, 2026 at 9:00 PM
🚨 EUVD-2026-44764
📊 5.4/10
🏢 taosdata

📝 TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Clou...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44764

#cybersecurity #infosec #cve #euvd
July 15, 2026 at 9:00 PM
CVE-2026-62349 - TDengine: Off-by-One Buffer Overflow
CVE ID : CVE-2026-62349

Published : July 15, 2026, 7:18 p.m. | 15 minutes ago

Description : TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/lib...
CVE-2026-62349 - TDengine: Off-by-One Buffer Overflow
TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks space for only one byte before processing SQL string escape sequences \%, \_, or \x, allowing a one-byte out-of-bounds write to the stack buffer tmpTokenBuf that can cause denial of …
cvefeed.io
July 15, 2026 at 8:53 PM
CVE-2026-62351 - TDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read in transDecompressMsg
CVE ID : CVE-2026-62351

Published : July 15, 2026, 7:18 p.m. | 15 minutes ago

Description : TDengine is a time-series database optimized for Internet of Thing...
CVE-2026-62351 - TDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read in transDecompressMsg
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMsg.contLen when pHead->comp == 1 without first validating that the RPC packet contained the 8-byte STransCompMsg structure, causing an unauthenticated out-of-bounds read, uncontrolled allocation, integer underflow, and server crash. This issue is fixed …
cvefeed.io
July 15, 2026 at 9:15 PM
CVE-2026-62353 - TDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetToken
CVE ID : CVE-2026-62353

Published : July 15, 2026, 7:18 p.m. | 15 minutes ago

Description : TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, ...
CVE-2026-62353 - TDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetToken
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null terminator, allowing an authenticated user who can submit SQL queries to crash the server …
cvefeed.io
July 15, 2026 at 8:36 PM
🚨 EUVD-2026-44771
📊 5.4/10
🏢 taosdata

📝 TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() increme...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44771

#cybersecurity #infosec #cve #euvd
July 15, 2026 at 9:00 PM