Schneider Electric PowerChute Serial Shutdown
CISA and Schneider Electric warn that PowerChute Serial Shutdown 1.5 and prior lack brute-force protection, allowing unauthorized account access via unlimited authentication attempts.
CVE-2026-13348 (CWE-307, CVSS 5.3) in Schneider Electric PowerChute Serial Shutdown versions 1.5 and prior lets attackers perform an arbitrary number of authentication attempts when redirect handling is disabled, gaining unauthorized access to user accounts. The UPS management software is deployed across commercial facilities, critical manufacturing, energy, and IT sectors worldwide. CISA advisory ICSA-26-260-07 recommends network isolation, VPN-protected remote access, and applying the vendor fix.