Critical vulnerabilities in Daktronics controllers put highway signs, digital billboards, and large LED displays in public spaces worldwide at risk. According to SecurityWeek, security researcher Thomas Jou — an undergraduate student at Princeton University — has identified three serious flaws that could allow remote attackers to take complete control of the devices, even without authentication. CISA has issued a related advisory, while Daktronics has already released corrective firmware updates.
See also: Oracle CSPU June 2026: 245 patches for critical vulnerabilities

Daktronics is an American company with a long history in the market for large-format digital displays, electronic scoreboards, and LED systems . The company's displays are found in school gyms, professional sports arenas, highways, international airports, and urban billboards around the world. This broad installed base makes the vulnerabilities particularly worrisome, as successful exploitation could impact critical public information infrastructure.
According to the notice published by CISA, the affected devices are the VFC-DMP-5000, DMP-5000 and DMP-8000. The vulnerabilities are found in firmware versions older than v8.117.xx, v9.43.xx and v10.34.xx, depending on the industry. CISA explicitly warned that “successful exploitation of these vulnerabilities could provide an unauthorized user with full root-level access and control of the system.”
Daktronics: What the three CVE vulnerabilities reveal
The first and most severe vulnerability, CVE-2026-28701, is a critical path traversal issue with a CVSS v3.1 score of 9.8 — almost the highest possible. It is located in the HTTP management interface and allows anyone, without authentication, to explore arbitrary file system paths, gaining access to files outside the intended directory. This is a classic first step to a deeper breach, as the attacker can discover credentials and sensitive configuration information.
The second vulnerability, CVE-2026-33560, concerns unrestricted file upload — the ability for an authorized user to upload arbitrary files to the device. Combined with the third vulnerability, CVE-2026-31928, which concerns default admin credentials that were not required to be changed during installation, an attacker could gain full access. Researcher Thomas Jou noted that during field testing, the majority of devices exposed to the internet were still using the default credentials — an extremely concerning finding.
See also: Rockwell Automation: Patch for critical vulnerabilities in ICS controllers

Jou described the exploit chain in detail: “ The path traversal vulnerability allows files to be read from the device, which is useful for identification and credential discovery. The file upload vulnerability could then allow an attacker to upload content or code that they control to the device. In practice, this means that an attacker could spoof what the sign displays — loading false or malicious messages on billboards and road signs, or even fake emergency alerts .”
Daktronics and OT/ICS security: How to protect yourself
This incident is a prime example of the risks that OT/ICS (Operational Technology / Industrial Control Systems) systems face when exposed to the internet without adequate protection. The management of Daktronics controllers via an HTTP-accessible interface, combined with weak network segmentation and default credentials, creates a classic high-risk scenario. The researcher identified multiple controllers exposed to the internet, noting that the responsibility for isolating installations lies with Daktronics customers , not the company itself.
Key recommendations for administrators of such systems include: immediately updating firmware to patched versions, removing any direct internet access for management interfaces, placing controllers behind a VPN or jump-host , and changing all default passwords. In addition, it is recommended to segment signaling networks so that a compromised controller cannot communicate with operational systems. For critical public signs, manual control backup procedures should be in place in case the systems need to be taken out of service for restoration.
The vulnerability disclosure process was conducted through CISA ’s VINCE platform . Jou reported the vulnerabilities in early January 2026, Daktronics responded promptly, and by early March 2026, the firmware patches were ready. The remaining time was spent preparing the coordinated notification and informing customers. Daktronics itself did not respond to a request for comment from SecurityWeek .
See also: Vulnerabilities in LangGraph allow remote code execution in AI agents

Overall, this case underscores once again that the security of public digital infrastructure cannot be taken for granted. Prompt application of available patches and isolation of systems from the public internet remain the most critical priorities for any organization managing Daktronics.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
