← All Advisories

CVE-2026-44108

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-44108

Key Details

CVECVE-2026-44108
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-07-30
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsPhoenix Contact CHARX SEC-3150, Phoenix Contact CHARX SEC-3100, Phoenix Contact CHARX SEC-3050, and Phoenix Contact CHARX SEC-3000
Classified asCWE-696 (Incorrect Behavior Order)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Phoenix ContactCHARX SEC-3150
Phoenix ContactCHARX SEC-3100
Phoenix ContactCHARX SEC-3050
Phoenix ContactCHARX SEC-3000
SubsystemsGeneral OT
SectorsMultiple

What to Know

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise. (NVD)

What to Do

Monitor Phoenix Contact's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-44108
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-44108