Vulnerabilities and exposures for PLCnext Control AXC F 2000 EA
The following sections list the security vulnerabilities (CVEs) that have been resolved in the respective firmware release. For more information about the specified CVE numbers, see:
Information on the Phoenix Contact PSIRT can be found at https://www.phoenixcontact.com/psirt.
Firmware releases 2026.x
2026.0.5 LTS2026.0.5 LTS
Released on 2026-07-20
Gnutls
- CVE-2026-42009
OpenSSL
- CVE-2026-7383
- CVE-2026-9076
- CVE-2026-34180
- CVE-2026-34182
- CVE-2026-42766
- CVE-2026-42767
- CVE-2026-42770
- CVE-2026-45445
- CVE-2026-45446
- CVE-2026-45447
Nginx
- CVE-2026-1642
- CVE-2026-9256
2026.0.4 LTS2026.0.4 LTS
Released on 2026-06-30
ACF
- CVE-2025-41670
Curl
- CVE-2026-1965
- CVE-2026-3783
- CVE-2026-3784
- CVE-2026-4873
- CVE-2026-5545
- CVE-2026-5773
- CVE-2026-6253
- CVE-2026-6276
- CVE-2026-6429
- CVE-2026-7168
Expat
- CVE-2026-45186
Gnutls
- CVE-2026-3832
- CVE-2026-3833
- CVE-2026-33845
- CVE-2026-42010
Glibc
- CVE-2026-4046
- CVE-2026-4437
- CVE-2026-4438
Kernel
- CVE-2026-31431
- CVE-2026-43037
- CVE-2026-43038
- CVE-2026-43186
- CVE-2026-43284
- CVE-2026-46300
Libexpat
- CVE-2026-32776
- CVE-2026-32777
- CVE-2026-32778
- CVE-2026-41080
Libssh
- CVE-2025-5987
- CVE-2026-3731
Nghttp2
- CVE-2026-27135
NTP
Via web-based Management service any parameters for the NTP/chrony configuration could be written to the configuration file and applied accordingly.
Openssh
Support of the obsolete “+ssh-rsa” algorithm has now been removed. In order to maintain compatibility with older clients, the algorithm was explicitly reactivated in previous updates, despite being communicated as removed.
- CVE-2026-35385
- CVE-2026-35386
- CVE-2026-35387
- CVE-2026-35388
- CVE-2026-35414
OpenSSL
- CVE-2026-28387
CVE-2026-28388
CVE-2026-28389
CVE-2026-28390
CVE-2026-31789
CVE-2026-31790
Python
- CVE-2025-12084
- CVE-2025-13836
- CVE-2025-13837
Remote Sync (rsync)
- CVE-2026-29518
- CVE-2026-41035
- CVE-2026-43617
- CVE-2026-43618
- CVE-2026-43619
- CVE-2026-43620
- CVE-2026-45232
WBM: Backup & Restore
- During decryption of an encrypted backup, a WBM alert containing internal security-related information was triggered when a user entered an incorrect password.
- During backup creation it was possible to set an encryption password with the length of one character.