One IO-Link Master Firmware, Three Brands, Twenty-One CVEs
CERT@VDE published advisories for Phoenix Contact, Pepperl+Fuchs and Carlo Gavazzi on the same day, all carrying the same CVE block and all pointing at a shared firmware base.

Three advisories landed at CERT@VDE on 16 September — VDE-2026-027 for Phoenix Contact, VDE-2026-014 for Pepperl+Fuchs and VDE-2026-028 for Carlo Gavazzi Automation. They carry the same block of CVEs, CVE-2026-27546 through CVE-2026-27565, with scores from 6.5 to 9.8. The reason is a shared IO-Link master firmware base below version 1.7.4, sold under three European brands.
Two entries score 9.8. CVE-2026-27546 lets an unauthenticated attacker exploit an authentication bypass in the _account_log function to log in as an admin. CVE-2026-27565 allows a malicious IODD file upload to place and execute a shell script with root privileges — and that script survives a reboot. An IODD is the device description file an engineer uploads as part of normal commissioning, which makes the upload path a routine action rather than an exotic one.
The rest of the set is equally uncomfortable: multiple command injections giving root-level execution across several endpoints, local file inclusion permitting arbitrary PHP execution, path traversal that exposes SSH private keys, unauthorised file upload, and information disclosure revealing password hashes.
The affected hardware includes Phoenix Contact IOL MA8 EIP DI8 (order number 1072839) and IOL MA8 PN DI8 (1072838), the Pepperl+Fuchs ICE2 and ICE3 families, and Carlo Gavazzi YL212 and YN115 devices. All three vendors point to firmware 1.7.8. Until that is applied, the advice is the usual one: minimise internet exposure, isolate the devices from corporate networks, use a VPN for remote access. Nozomi Networks researchers found the set and disclosed it through CERT@VDE.
What makes this batch instructive is that nothing in any datasheet tells a buyer these three products share a codebase. Only the matching CVE numbers do. It is a compact argument for the software bill of materials requirements arriving with the EU Cyber Resilience Act.