CERT@VDE disclosed two CVSS 9.8 vulnerabilities in 15 IO-Link industrial master models from Pepperl+Fuchs, Phoenix Contact, and Carlo Gavazzi Automation. CVE-2026-27546 is an authentication-bypass flaw in the _account_log function that can grant an unauthenticated attacker an administrator session, while CVE-2026-27565 is an IODD-file processing command-injection flaw that enables unauthenticated root-level command execution and can persist a malicious script on the device.
Affected products include Pepperl+Fuchs ICE2 and ICE3 series devices, Phoenix Contact IOL MA8 EIP DI8 and IOL MA8 PN DI8 models, and Carlo Gavazzi YL212 and YN115 models running firmware earlier than 1.7.4. The Canadian Centre for Cyber Security advises organizations to apply firmware 1.7.4 and follow vendor guidance; administrators should isolate management interfaces and restrict IODD uploads until remediation is complete. No public exploit or CISA Known Exploited Vulnerabilities catalog listing was reported at disclosure.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-927 identifying multiple security vulnerabilities affecting specified Pepperl+Fuchs ICE2 and ICE3, Phoenix Contact IOL MA8, and Carlo Gavazzi YL212 and YN115 industrial I/O devices. The advisory directed users to consult vendor advisories and apply necessary firmware updates; affected versions are earlier than 1.7.4.
CERT@VDE published advisory VDE-2026-027 disclosing CVE-2026-27546, an authentication-bypass flaw, and CVE-2026-27565, an OS command-injection flaw, affecting 15 IO-Link industrial master models from Pepperl+Fuchs, Phoenix Contact, and Carlo Gavazzi. Both primary vulnerabilities were rated CVSS 9.8; affected devices running firmware earlier than 1.7.4 should be upgraded to version 1.7.4.
CERT@VDE reported that Phoenix Contact IOL MA8 EIP DI8 and IOL MA8 PN DI8 firmware is vulnerable to authentication bypass, command injection, local file inclusion, path traversal, and modified-schema attacks. The flaws can enable code execution and disclosure of sensitive information, including password hashes and private keys.
CERT@VDE reported that Carlo Gavazzi YL212 and YN115 devices have authentication-bypass, command-injection, local-file-inclusion, path-traversal, and modified-schema vulnerabilities. The flaws could enable code execution or exposure of sensitive data, including password hashes and private keys.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcethreataft.com
Open sourcecertvde.com
Open sourcecertvde.com
Open sourcecertvde.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.