Security researchers discovered severe industrial firmware vulnerabilities across multiple automation vendors. Three distinct companies released coordinated security advisories detailing critical authentication bypass flaws. Attackers can exploit twenty unique security defects to compromise factory networks completely. Organizations must apply the latest software updates to protect their operational technology environments.
TL;DR
Three major industrial equipment vendors disclosed severe industrial firmware vulnerabilities affecting shared controller software. These critical flaws allow remote attackers to bypass authentication and execute unauthorized commands. Plant operators must update affected units to firmware version 1.7.8 immediately to prevent system compromises.
- Total: 3 CVEs
- Severity: 2 Critical · 1 High
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-27565
- Action: Apply the latest security updates now
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-27565 | 9.8 | Remote code execution via uploading a malicious IODD file | 1.7.4 | Not exploited |
| CVE-2026-27546 | 9.8 | Authentication Bypass in _account_log | 1.7.4 | Not exploited |
| CVE-2026-27557 | 7.5 | Path Traversal in /index.php/view_uploaded_iodd_file | 1.7.4 | Not exploited |
Why This Threat Matters
Industrial control devices manage critical manufacturing and energy processes. Severe security flaws in these units expose entire production lines to remote sabotage. The official advisories warn that “Authentication can be bypassed”. They also state that “Code with high access rights can be executed on the device”. Consequently, remote attackers can alter device operations or extract sensitive data like private encryption keys. This compromises the fundamental integrity of the industrial network.
How the Attack Works
The industrial firmware vulnerabilities stem from improper input validation and broken access controls. The most critical defect, CVE-2026-27546, provides a direct authentication bypass path. Attackers manipulate the system login functions to gain administrative privileges without valid credentials.
Another critical flaw, CVE-2026-27565, allows complete remote code execution. An unauthenticated remote attacker can upload a malicious IODD configuration file. This malicious file places and executes a shell script with root privileges. The rogue script remains active in memory even after the device reboots.
The platform also suffers from numerous command injection vulnerabilities within its API endpoints. For instance, CVE-2026-27564 and CVE-2026-27563 allow high-privileged remote attackers to exploit the data storage endpoint. By sending crafted HTTP requests, attackers can execute arbitrary commands with root privileges. Similarly, CVE-2026-27556 introduces a dangerous local file inclusion vulnerability. A low-privileged user can exploit the parameter saving endpoint to execute arbitrary PHP code directly on the controller.
Furthermore, attackers can abuse CVE-2026-27557 to perform path traversal attacks. This specific exploit allows them to read the private SSH keys stored securely on the device. Currently, security researchers have not confirmed any active in-the-wild exploitation for these flaws. Researchers Gabriele Quagliarella and Luca Borzacchiello from Nozomi Networks discovered and reported these defects.
Affected Versions
These authentication bypass flaws affect multiple product lines sharing the same core firmware package. Affected hardware includes Pepperl+Fuchs ICE2 and ICE3 network modules. They also impact Phoenix Contact IOL MA8 PN DI8 and IOL MA8 EIP DI8 hardware devices. Additionally, Carlo Gavazzi Automation YL212 and YN115 series controllers contain the exact same software defects. The vulnerable firmware versions span all releases prior to version 1.7.4 across all three vendors.
Patch and Mitigation Steps
Vendors released firmware version 1.7.8 to resolve these dangerous industrial firmware vulnerabilities. Network administrators should install this critical update immediately. If immediate patching is impossible, facility operators must isolate the vulnerable devices.
The official guidance explicitly directs users to “Minimize network exposure for affected products and ensure that they are not accessible via the Internet”. Furthermore, engineering teams must restrict remote access to secure virtual private networks. You can review the comprehensive technical details in the Pepperl+Fuchs security advisory, the Phoenix Contact security advisory, and the Carlo Gavazzi security advisory.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!