CVE-2026-44092
published 2026-07-30CVE-2026-44092: An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT…
PriorityP258critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.42%
35.8th percentile
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenix_contact | charx_sec-3000 | >= 1.0.0 < 1.9.1 | 1.9.1 |
| phoenix_contact | charx_sec-3050 | >= 1.0.0 < 1.9.1 | 1.9.1 |
| phoenix_contact | charx_sec-3100 | >= 1.0.0 < 1.9.1 | 1.9.1 |
| phoenix_contact | charx_sec-3150 | >= 1.0.0 < 1.9.1 | 1.9.1 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ModbusServer: ModbusServer: Integrity and availability loss via malicious MQTT input injection
vendor_redhat·2026-07-30·CVSS 9.1
CVE-2026-44092 [CRITICAL] CWE-94 ModbusServer: ModbusServer: Integrity and availability loss via malicious MQTT input injection
ModbusServer: ModbusServer: Integrity and availability loss via malicious MQTT input injection
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
A flaw was found in ModbusServer. An unauthenticated remote attacker can inject malicious input into the application due to a lack of input validation when fetching data from MQTT. This vulnerability may lead to a loss of data integrity and system availability.
GHSA
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT.
ghsa_unreviewed·2026-07-30
CVE-2026-44092 [HIGH] CWE-93 An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT.
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
No detection rules found.
No public exploits indexed.
2026-07-30
Published