CISA alerts on Schneider Electric vulnerability CVE-2026-4827
Owners of Schneider Electric Easergy, EcoStruxure, PowerLogic and Saitel devices must apply the supplied patch immediately to prevent session hijacking.

CISA has issued a security advisory identifying CVE-2026-4827 in a range of Schneider Electric products. The vulnerability is classified as CWE-331 Insufficient Entropy and carries a CVSS v3 score of 8.3. Exploitation could enable session hijacking and unauthorized operations on affected systems.
The notice lists affected versions, including Easergy MiCOM C264 versions D7.33 and earlier, Easergy MiCOM P139 prior to P139.678.700, MiCOM P437 prior to P437.678.700, MiCOM P439 prior to P439.678.700, MiCOM P532 prior to P532.678.700, MiCOM P539 prior to P539.678.700, MiCOM P631 prior to P631.678.700, MiCOM P632 prior to P632.678.700, MiCOM P633 prior to P633.678.700, MiCOM P634 prior to P634.678.700, MiCOM P138 prior to P138.677.700, MiCOM P436 prior to P436.677.701, MiCOM P438 prior to P438.677.701, MiCOM P638 prior to P638.677.700, MiCOM C434 prior to C434.679.700, EcoStruxure Power Automation System Gateway (EPAS-GTW) version 6.4.616.200.100 and earlier, EPAS-UI version 3.0.3 and earlier, EcoStruxure Power Operation 2022_CU6 and earlier, 2024_CU2 and earlier, iPMFLS version 64.2025.0.13 and earlier, PowerLogic P5 version 02.502.103 and earlier, PowerLogic P7 version 02.002.002 and earlier, PowerLogic T300 version 2.9.4 and earlier, PowerLogic T500 version 11.08.02 and earlier, Easergy C5 version 1.1.17 and earlier, and all Easergy MiCOM P40 series models with Protocol Option bits G, H or L.
Schneider Electric recommends applying the vendor-supplied fix without delay and following its cybersecurity best-practice guidance, which includes network isolation, physical security of controllers, limiting remote access to VPNs, and sanitizing removable media before use.
An internal Schneider Electric researcher reported the vulnerability to CISA. Organizations can obtain remediation assistance from their local Schneider representative or Schneider Industrial Cybersecurity Services via the company's support portal.
Further reading


