VulnSea

Schneider Electric has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 8.6 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) (2), Modicon M580 (1), PowerLogic T300 (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.6
Publish → KEV
—
Last 90 days
5 prev 0

Products

  • EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) 2
  • Modicon M580 1
  • PowerLogic T300 1
  • SCADAPack 47x 1
5
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Schneider Electric vulnerabilities

CVEs affecting Schneider Electric, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-81861Medium· 5.9PoC
2w ago

CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.

CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.

▾ TwilightSchneider Electric · SCADAPack 47xEPSS 0.54%via NVD
CVE-2026-3869Critical· 9.2
2w ago

CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running…

CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running…

▾ MidnightSchneider Electric · Modicon M580EPSS 0.54%via NVD
CVE-2026-77120High· 8.7
2w ago

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause privilege escalation to root and unauthorized execution of administrative functions when an authenti…

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause privilege escalation to root and unauthorized execution of administrative functions when an authenti…

▾ TwilightSchneider Electric · PowerLogic T300EPSS 0.67%via NVD
CVE-2026-8044High· 8.6
2w ago

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as back…

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as back…

▾ TwilightSchneider Electric · EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert)EPSS 0.67%via CVEORG
CVE-2026-19233High· 8.6
2w ago

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server e…

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server e…

▾ TwilightSchneider Electric · EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert)EPSS 0.70%via NVD
Schneider Electric vulnerabilities (CVEs) · VulnSea