Schneider Electric ICS advisories: CVE-2026-4827 session-hijacking flaw (CVSS 8.3) in grid products; Canada flags NetBotz and PowerChute vulnerabilities (AV26-871)
CISA republished ICSA-26-169-07 (Update A) for CVE-2026-4827 (CVSS 8.3), an insufficient-entropy flaw in session management that could enable session hijacking across Easergy, EcoStruxure, PowerLogic, and Saitel grid products; separately, Canada's Cyber…
Two Schneider Electric industrial-control-systems advisories emerged within 24 hours. On 2026-09-02, the Canadian Centre for Cyber Security issued advisory AV26-871, noting vulnerabilities as of September 1, 2026 in NetBotz 5-750/755 versions 5.5.2 and prior (multiple vulnerabilities) and in PowerChute Serial Shutdown versions 1.5 and prior (improper restriction of excessive authentication attempts), urging users to review Schneider Electric's notifications and apply updates and mitigations. On 2026-09-03, CISA republished ICSA-26-169-07 as Update A, detailing CVE-2026-4827 (CWE-331 insufficient entropy in session management, CVSS 8.3) affecting Easergy MiCOM relays and C5, EcoStruxure Power Automation (EPAS-GTW, EPAS-UI, iPMFLS), EcoStruxure Power Operation, PowerLogic P5/P7/T300/T500, and Saitel DP/T150 RTUs, with dozens of fixed firmware versions listed. Successful exploitation could enable session hijacking and unauthorized operations in energy, chemical, critical manufacturing, and water sectors. The two advisories cover different product sets and do not conflict; fixes are available and no exploitation is reported.
- CVE-2026-4827 (CVSS 8.3, CWE-331 insufficient entropy in session management) could enable session hijacking and unauthorized operations (CISA ICSA-26-169-07 Update A, 2026-09-03)
- Affected lines for CVE-2026-4827: Easergy MiCOM relays and C5, EcoStruxure Power Automation (EPAS-GTW, EPAS-UI, iPMFLS), EcoStruxure Power Operation, PowerLogic P5/P7/T300/T500, and Saitel DP/T150 RTUs; Update A lists dozens of fixed…
- Sectors at risk from CVE-2026-4827: energy, chemical, critical manufacturing, and water infrastructure
- Canadian advisory AV26-871 (published 2026-09-02; vulnerabilities as of September 1, 2026): NetBotz 5-750/755 versions 5.5.2 and prior affected by multiple vulnerabilities
- PowerChute Serial Shutdown versions 1.5 and prior contain an improper restriction of excessive authentication attempts flaw
- Fixes/mitigations are available for both advisories; CISA reports no exploitation; the Cyber Centre urges users to apply Schneider Electric updates and mitigations
- The advisories cover distinct product sets (CISA: grid/RTU products; Canada: NetBotz and PowerChute); no source disagreements or conflicting figures were found
Coverage timelineoldest first · each row is one article
- · 14d ago[Control systems] Schneider Electric security advisory (AV26-871)
Canadian Centre for Cyber Security· 24
Canada's Cyber Centre relayed Schneider Electric advisories for vulnerabilities in NetBotz 5-750/755 (5.5.2 and prior) and PowerChute Serial Shutdown (1.5 and prior).
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-4827 | CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑mana CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections. NVD description · AI analysis pending | 8.7 | <1% | — | — |