CVE-2026-27565: Carlo Gavazzi Automation YL212CEI8M1IO

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.

Affected products

Published 2026-09-16. Last modified 2026-09-16.