[Control Systems] Phoenix Contact security advisory (AV26-927)
Canadian Cyber Centre warns Phoenix Contact, Pepperl+Fuchs, and Carlo Gavazzi I/O devices need firmware 1.7.4 to fix multiple vulnerabilities.
Canada's Cyber Centre issued advisory AV26-927 covering multiple vulnerabilities in Phoenix Contact ICE2/ICE3 and IOL MA8 EIP/PN devices, plus related Pepperl+Fuchs and Carlo Gavazzi YL212/YN115 products. Firmware versions prior to 1.7.4 are affected across roughly 15 models. Administrators are encouraged to review vendor advisories and apply available updates.
- Advisory AV26-927 covers Phoenix Contact, Pepperl+Fuchs, and Carlo Gavazzi devices
- Firmware before 1.7.4 is affected across ICE2/ICE3 and IOL MA8 models
- Administrators urged to review vendor links and apply updates
Full article153 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-927
Date: September 16, 2026
As of September 16, 2026, Phoenix Contact is affected by vulnerabilities in the following products:
- ICE2-8IOL-G65L-V1D
- Prior to 1.7.4
- ICE2-8IOL-K45P-RJ45
- Prior to 1.7.4
- ICE2-8IOL-K45S-RJ45
- Prior to 1.7.4
- ICE2-8IOL1-G65L-V1D
- Prior to 1.7.4
- ICE3-8IOL-G65L-V1D
- Prior to 1.7.4
- ICE3-8IOL-G65L-V1D-Y
- Prior to 1.7.4
- ICE3-8IOL-K45P-RJ45
- Prior to 1.7.4
- ICE3-8IOL-K45S-RJ45
- Prior to 1.7.4
- ICE3-8IOL1-G65L-V1D
- Prior to 1.7.4
- IOL MA8 EIP DI8
- Prior to 1.7.4
- IOL MA8 PN DI8
- Prior to 1.7.4
- YL212CEI8M1IO
- Prior to 1.7.4
- YL212CPN8M1IO
- Prior to 1.7.4
- YN115CEI8RPIO
- Prior to 1.7.4
- YN115CPN8RPIO
- Prior to 1.7.4
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
- Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
- Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
- Phoenix Contact Advisories
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/control-systems-phoenix-contact-security-advisory-av26-927