[Control systems] Schneider Electric security advisory (AV26-912)
Canada's Cyber Centre relays a Schneider Electric advisory covering multiple vulnerabilities in EcoStruxure IT Data Center Expert and PowerLogic T300, urging users to apply updates.
The Canadian Centre for Cyber Security issued advisory AV26-912 noting that as of September 9, 2026 Schneider Electric is affected by vulnerabilities in EcoStruxure IT Data Center Expert versions 9.1.2 and prior, and PowerLogic T300 versions 2.9.8-5620 and prior. The issues include an improper neutralization of special elements used in an OS command on the PowerLogic T300. The advisory recommends reviewing vendor notifications, performing suggested mitigations, and applying necessary updates.
- Affects EcoStruxure IT Data Center Expert (v9.1.2 and prior) and PowerLogic T300 (v2.9.8-5620 and prior)
- Includes an OS command injection issue on the PowerLogic T300
- Administrators urged to apply vendor mitigations and updates
Full article92 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-912
Date: September 11, 2026
As of September 9, 2026, Schneider Electric is affected by vulnerabilities in the following products:
- EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert)
- Versions 9.1.2 and prior
- PowerLogic T300
- Versions 2.9.8-5620 and prior
The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/control-systems-schneider-electric-security-advisory-av26-912