New data from the Ridge Security Research Team disclosed CVE-2026-42542, a pre-authentication vulnerability in TDengine, an open-source distributed time-series database used in industrial telemetry, energy, utilities, connected vehicles and IoT environments.

The vulnerability stems from an integer underflow in TDengine’s handling of a length field in its custom binary RPC protocol on TCP port 6030.

Ridge Security said the failure can result in lost in-flight writes and loss of visibility for OT (operational technology) and telemetry workloads.

Ridge Security researchers identified a vulnerability with confirmed denial-of-service impact, wherein a single crafted packet to the RPC port reliably crashes taosd.

Since this vulnerability requires network access to the RPC port, removing that access eliminates the exposure regardless of patch status.