INCIBE flags PLCnext, Quay, and OpenShift flaws
INCIBE-CERT issued alerts on PLCnext, Red Hat Quay, and OpenShift components, including one critical flaw with no active exploitation seen.
INCIBE-CERT issued several August alerts on vulnerabilities in Phoenix Contact’s PLCnext, Red Hat Quay, and OpenShift components. In the PLCnext case, the available coverage indicates that one flaw was critical and that, according to the advisory table, there was no recorded active exploitation.
INCIBE-CERT issued several August alerts on vulnerabilities in Phoenix Contact’s PLCnext, Red Hat Quay, and OpenShift components. In the PLCnext case, the available coverage indicates that one of the flaws was critical and that, according to the advisory table, there was no recorded active exploitation. Phoenix Contact had also already released an official advisory with the firmware fix.
What did INCIBE say about Phoenix Contact PLCnext?
INCIBE-CERT published alert INCIBE-2026-553 for three vulnerabilities in Phoenix Contact’s PLCnext firmware, while Moncloa’s coverage said one of them was critical and that, according to the advisory’s own table, there was no recorded active exploitation. Phoenix Contact, for its part, said the flaws affect versions earlier than PLCnext 2026.0.3.
Phoenix Contact’s official advisory says the issues affect PLCnext firmware and that at least one of them can lead to a denial-of-service condition in the PLCnext Engineer communication interface. The fix is tied to updating to PLCnext 2026.0.3 or later, with reference to a CSAF advisory that identifies affected products and corrected versions.
IoT News Digest 2633 also noted that Phoenix Contact had fixed SQL injection vulnerabilities and denial-of-service conditions in PLCnext, and placed them in communication components exposed on OT networks. According to that summary, the potential impact grows if PLCs are reachable from non-segmented networks.
What other alerts did INCIBE publish those days?
INCIBE-CERT also issued alerts for CVE-2026-73047, CVE-2026-71567, CVE-2026-49431, and CVE-2026-74243, with different severity levels and analysis states. That group includes an information disclosure flaw, a command injection issue in OpenShift, one vulnerability still under analysis, and a medium-severity Red Hat Quay flaw that could cause denial of service.
CVE-2026-73047 was classified as high severity and mapped to CWE-200, meaning information disclosure. CVE-2026-71567 was also rated high severity and linked to an operating system command injection issue in openshift-metal3/fakefish.
NVD describes CVE-2026-71567 as a script pattern where shell variables are injected without quotes into command lines or manifests, with particular impact on parameters such as the image URL and BMC credentials. The CVE aggregator lists it as remotely exploitable and as CWE-78, though it says no public exploits were available at the time of publication.
INCIBE-CERT marked CVE-2026-49431 as pending analysis. CVE-2026-74243 was published with medium severity and tied to a Red Hat Quay flaw that could let an unauthenticated attacker flood the notification queue and trigger denial of service.
How does the picture look for Red Hat Quay and OpenShift?
The available references show a family of flaws in Red Hat Quay and related OpenShift services, with limited risk and no public evidence of widespread exploitation at the time they were logged. OpenCVE reported similar issues in Quay 3 and the Red Hat OpenShift Update Service, with moderate severity and no signs of inclusion in CISA KEV.
In other related cases, OpenCVE described weaknesses in JWT validation for federated accounts and in Stripe webhook signature verification. According to that analysis, an attacker with a valid token or access to public endpoints could bypass authentication controls, alter build quotas, or reach unauthorized resources.
For the Quay vulnerabilities, OpenCVE also said there were no known exploits and that the likelihood of exploitation remained uncertain because EPSS metrics were unavailable. That context puts INCIBE-CERT’s alert on CVE-2026-74243 in perspective, since it remains a limited-impact flaw tied to denial of service.
Sources
- CVE-2026-71567 Detailnvd.nist.gov· NVD (NIST)
- CVE-2026-73047incibe.es· INCIBE-CERT
- CVE-2026-71567 - Exploits & Severityfeedly.com· Feedly CVE / EUVD aggregator
- El INCIBE-CERT alerta de tres vulnerabilidades en PLCnext de Phoenix Contactmoncloa.com· Moncloa
- CVE-2026-74241 - Vulnerability Detailsapp.opencve.io· OpenCVE
- CVE-2026-49431incibe.es· INCIBE-CERT
- CVE-2026-74240 - Vulnerability Detailsapp.opencve.io· OpenCVE
- CVE-2026-74243incibe.es· INCIBE-CERT
- CVE-2026-74244 - Vulnerability Detailsapp.opencve.io· OpenCVE
- CVE-2026-71567incibe.es· INCIBE-CERT
- CVE-2025-41770: PLCnext Engineer DoS Vulnerabilitysentinelone.com· SentinelOne
- IoT News Digest 2633iotdigest.substack.com· IoT News Digest (Substack)



