[Control Systems] Phoenix Contact Security Advisory (AV26-378)

Number: AV26-378
Date: April 22, 2026

On April 22, 2026, Phoenix Contact published a security advisory to address vulnerabilities in the following products:

  • AXC – multiple versions
  • BCP – multiple versions
  • CATAN C1 EN – versions prior to1.12.3
  • CELLULINK – versions prior to 2025.6.3
  • CHARX SEC-3XXX – versions prior to 1.9.0
  • CLOUD CLIENT 101T-TX/TX –versions prior to 3.7.8
  • Energy AXC PU – – versions prior to V04.27.00.00
  • FL MGUARD – versions prior to 10.6.0
  • FL NAT – multiple versions
  • FL SWITCH – multiple versions
  • FL TIMESERVER NTP – versions prior to 5.0.71.101
  • FL WLAN – multiple versions
  • GTC – multiple versions
  • ILC 2xxx – multiple versions
  • NFC – multiple versions
  • PLCnext Control – versions prior to 3.53
  • RFC – multiple versions
  • SMART RTU AXC – – multiple versions
  • TC CLOUD CLIENT – multiple versions
  • TC ROUTER – multiple versions
  • TC TIMESERVER NTP – versions prior to 5.0.71.101

The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, once available.

Date modified: