CISA republishes Schneider Electric PowerChute vulnerability advisory

Operators of Schneider Electric PowerChute Serial Shutdown version 1.5 or earlier must apply the vendor fix after the advisory's 2026-09-17 release.

Black cables and wires connected to the back of modular LED display panels

CISA republished a Schneider Electric advisory on 2026-09-17 that identifies CVE-2026-13348 in PowerChute Serial Shutdown versions 1.5 and prior, as well as version 1.6. The vulnerability is rated CVSS v3 5.3 and is classified as CWE-307: Improper Restriction of Excessive Authentication Attempts.

The flaw allows an attacker to perform an arbitrary number of authentication attempts when redirect handling is disabled, potentially gaining unauthorized access to user accounts and disrupting operations or exposing system data.

Schneider Electric advises affected users to apply the remediation provided by the vendor. The company also recommends standard cybersecurity practices such as isolating control system networks behind firewalls, using VPNs for remote access, and securing physical access to controllers.

The notice is a verbatim republication of Schneider Electric CPCERT advisory SEVD-2026-223-01, originally released on 2026-08-11. CISA provides the information "as-is" without warranty and does not endorse any commercial product.

CISA further urges organizations to minimize network exposure of control system devices, conduct impact analysis before deploying defensive measures, and report any suspected malicious activity to CISA for tracking.

Keep reading