CVE-2026-44100: Phoenix Contact Charx Sec-3000
Critical severity, CVSS 9.4. EPSS: 0.5% chance of exploitation in the next 30 days.
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.
Affected products
- Phoenix Contact Charx Sec-3000: from 1.0.0, before 1.9.1 (fixed in 1.9.1)
- Phoenix Contact Charx Sec-3050: from 1.0.0, before 1.9.1 (fixed in 1.9.1)
- Phoenix Contact Charx Sec-3100: from 1.0.0, before 1.9.1 (fixed in 1.9.1)
- Phoenix Contact Charx Sec-3150: from 1.0.0, before 1.9.1 (fixed in 1.9.1)
Published 2026-07-30. Last modified 2026-07-30.