A Licensing Runtime Pulls Five Flaws Into TRUMPF's Shop-Floor Software
CERT@VDE advisory VDE-2026-091 lists Oseon, the TruTops family and TecZone as exposed through vulnerable Wibu CodeMeter Runtime builds. The fix comes from Wibu, not TRUMPF.

TRUMPF has reported through CERT@VDE that most of its shop-floor software stack is exposed by vulnerable builds of a component it does not write. Advisory VDE-2026-091, published 15 September, names Oseon, TruTops Boost, TruTops Weld, TruTops Cell, TruTops Mark 3D, TecZone Laser, TecZone Cut Laser, TecZone Bend, TRUMPF License Expert and Programming Tube.
The component is Wibu CodeMeter Runtime, the dongle and licence-management service that underpins a large share of German industrial software. Five CVEs are listed. CVE-2026-81573, an improper access control at 8.6, lets remote attackers execute restricted commands and potentially take over the CodeMeter WebAdmin interface. CVE-2026-81574 is a format string flaw at 8.2, giving information disclosure and denial of service. CVE-2026-81572 is link following at 7.8, a local privilege escalation via arbitrary file deletion. CVE-2026-81576, weak session authentication at 7.7, allows session IDs to be brute-forced to reach other users' licence data. CVE-2026-81575 is a missing buffer check at 7.5, crashing the service remotely.
Remediation is a CodeMeter Runtime update — version 9.10 on Windows 11 or 8.41a on Windows 10 — obtained from Wibu rather than from TRUMPF.
That split is the point. CodeMeter runs as a service on the programming PCs that generate NC code for laser cutting and bending cells, and those machines are usually managed by production rather than IT. A machine builder can publish an advisory but cannot ship the fix, and the customer has to trust that updating a licensing runtime will not break the software it licenses — which is exactly the hesitation that leaves these components out of date for years.