A newly disclosed zero-day vulnerability in TDengine, an open-source time-series database, carries a high-severity rating and can be exploited with just one network packet to crash servers. The flaw is particularly concerning for operational technology (OT) environments, where availability is critical and unplanned downtime can disrupt physical processes.

According to Dark Reading, the vulnerability exists in TDengine's handling of certain network input, allowing an unauthenticated remote attacker to trigger a denial-of-service condition. Because TDengine is deployed across industrial, IoT, energy, and automotive settings, the exposure is broad, and affected organizations should treat the issue as urgent.

The report does not indicate that a patch is already available, so operators relying on TDengine may need to apply mitigations such as network segmentation or access controls while monitoring vendor guidance. Given the low barrier to exploitation, the vulnerability should be prioritized in any security review of systems using the database.