ZeroHour

CVE-2026-3869

large

Flawed Authentication Algorithm in Schneider Electric PLC Enables Full Compromise

CVSS 4.0
9.2 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-3869 is a critical (CVSS 4.0 score 9.2) incorrect implementation of an authentication algorithm (CWE-303) in a Schneider Electric programmable logic controller (PLC), disclosed and patched as part of Schneider Electric's ICS Patch Tuesday release. The flaw is reachable over the network with no privileges or user interaction required, but it carries elevated attack requirements: it comes into play when the PLC is running an application project with a lower application level, which is the configuration precondition for exploitation. An attacker who meets those conditions can defeat the controller's authentication mechanism and cause a complete loss of confidentiality, integrity and availability of the PLC (VC:H/VI:H/VA:H), meaning they could read, modify or disrupt the running control process. Affected users are operators of the impacted Schneider Electric PLC line; the available data does not name the specific model or firmware versions, so operators should confirm their exposure against the official Schneider notification. No public proof-of-concept is known and the flaw is not listed in CISA's KEV, with no reports of exploitation in the wild to date.

What to do: Check the Schneider Electric security notification for CVE-2026-3869 to confirm whether your PLC model and firmware fall in the affected range, and apply the vendor's published firmware update. Until patched, restrict exposure by firewalling or allowlisting the PLC's management and protocol ports and keeping OT networks segmented, and verify whether the controller is running an application project with a lower application level, since that configuration is the precondition for exploitation.

Affected
Schneider Electric PLC (specific model line not identified in the available data)
Estimated exposure
largelikely on the order of tens of thousands of installed controllers (estimate; affected model line unspecified) — Schneider Electric is one of the largest PLC vendors and public internet scans routinely show tens of thousands of exposed Schneider/Modicon controllers, but the specific affected model is not named in the available data, so this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC.

Weakness
CWE-303
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

September ICS Patch Tuesday brings critical fixes from Schneider Electric, Siemens, and Aveva, including CVSS 9.2 authentication flaw CVE-2026-3869 in Modicon M580 controllers.

Schneider Electric's September advisories include a critical authentication vulnerability, CVE-2026-3869 with a CVSS score of 9.2, in Modicon M580 and Modicon M580 Safety controllers, plus high-severity bugs in PowerLogic T300 and EcoStruxure IT Data Center Expert. Siemens published nine new advisories, four rated critical across Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT, and began rolling out fixes for CVE-2026-31431, a 7.8-rated Linux kernel flaw enabling root shell access. Aveva disclosed four flaws in Pipeline Integrity Monitor's PIMBoards, including a hardcoded encryption key and MD5-hashed passwords, plus an unsafe deserialization issue in Enterprise SCADA. Rockwell Automation separately issued nine advisories covering RSLinx Classic and multiple controller products.