CVE-2026-44108 CRITICAL

CVE-2026-44108: Firewall bypass during shutdown

Vendor Phoenix Contact
Product CHARX SEC-3150
Weakness CWE-696
Published July 30, 2026
Last update July 30, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.

Key dates

02Disclosure timeline

July 30, 2026 CVE published
July 30, 2026 Record updated