securityonline.info 8/14/2026, 8:51:14 AM · external

Critical RCE flaw in Phoenix Contact PLCnext firmware, patch urged

Critical RCE flaw in Phoenix Contact PLCnext firmware, patch urged
CyberSIXT Evidence Panel

PHOENIX Contact disclosed three vulnerabilities in PLCnext firmware on August 12, 2026, including a critical flaw (CVE-2025-41769) resulting in unauthenticated buffer overflow with a CVSS score of 9.8, allowing remote code execution. Other vulnerabilities involve a Denial of Service (CVE-2025-41770) with a CVSS score of 7.5 and a SQL injection (CVE-2025-41771) with a CVSS score of 4.3. The SQL injection risk affects only the local SQLite database without confirmed exploitation reported.

Users are advised to update to firmware version 2026.0.3, which addresses all issues, or take mitigation steps such as firewalls and limited network access.

View full article

Article by CyberSIXT