Vendor
Schneider Electric vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 27 vulnerabilities in Schneider Electric: 0 in the last 7 days and 10 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-6625, was published on 17 September 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 10
- Critical, all time
- 0
- Exploited in the wild
- 0
About Schneider Electric
A multinational company specializing in energy management and industrial automation.
Schneider Electric technologies
Latest Schneider Electric vulnerabilities
- CVE-2025-6625: Schneider Electric Modicon M340 improper input validation in FTP servicehighCVSS 7.5
- CVE-2026-81861: CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information…highCVSS 6.5EPSS 0.5%
- CVE-2026-3869: Schneider Electric PLC authentication algorithm incorrect implementationinfoEPSS 0.5%
- CVE-2026-13348: CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to…highCVSS 5.3EPSS 0.3%
- CVE-2026-13337: Schneider Electric NetBotz SQL injection in Hibernate query interfaceinfoEPSS 0.2%
- CVE-2026-13336: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists…highCVSS 6.4EPSS 0.6%
- CVE-2024-10085: Schneider Electric OPC UA resource exhaustion denial of serviceinfoEPSS 0.3%
- CVE-2026-14354: Schneider Electric EcoStruxure Cybersecurity Admin Expert credential protection bypassinfoCVSS 8.7
- CVE-2026-12927: Schneider Electric IGSS Definition out-of-bounds write via CGF importinfoCVSS 8.4
- CVE-2026-0667: Schneider Electric SCADAPack code execution in Modbus TCP protocol handlinginfoCVSS 9.3
- CVE-2026-9718: Schneider Electric PowerLogic P7 reachable assertion in network serviceinfoCVSS 6.9
- CVE-2026-9717: Schneider Electric PowerLogic P7 OS command injectioninfoCVSS 8.6
- CVE-2026-9716: Schneider Electric PowerLogic P7 NULL pointer dereference DoSinfoCVSS 8.7
- CVE-2026-9651: Schneider Electric RTU incorrect permission assignment in system filesinfoCVSS 6.7
- CVE-2026-9650: Schneider Electric EasyLogic and Saitel RTU unprotected credentialsinfoCVSS 8.7
- CVE-2026-8045: Schneider Electric Data Center Expert XXE in SOAP serviceinfoCVSS 7.1
- CVE-2026-6332: Schneider Electric EcoStruxure Machine Expert HVAC cleartext storagehighCVSS 7.5EPSS 0.0%
- CVE-2026-6866: Schneider Electric EcoStruxure Panel Server insecure default credentialshighCVSS 7.5EPSS 0.3%
- CVE-2026-6865: Schneider Electric path traversal in server-side file processinginfoCVSS 7.1
- CVE-2026-4827: Schneider Electric products insufficient entropy in session managementinfoCVSS 8.7
- CVE-2026-2273: Schneider Electric EcoStruxure Automation Expert code injectionhighCVSS 8.2EPSS 0.2%
- CVE-2026-1286: Schneider Electric EcoStruxure Foxboro DCS deserialization in project filesmediumCVSS 6.5EPSS 0.3%
- CVE-2025-13902: Schneider Electric Modicon Controllers XSS in Web ServermediumCVSS 5.4EPSS 0.4%
- CVE-2025-13901: Schneider Electric Modicon DoS in Machine Expert protocolmediumCVSS 5.3EPSS 0.5%
- CVE-2025-11739: Schneider Electric EcoStruxure Power products unsafe deserializationhighCVSS 7.8EPSS 0.2%
Most severe Schneider Electric vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-2273: Schneider Electric EcoStruxure Automation Expert code injectionhighCVSS 8.2EPSS 0.2%
- CVE-2025-13845: Schneider Electric Rapsody use-after-free in project file parsinghighCVSS 7.8EPSS 0.4%
- CVE-2025-11739: Schneider Electric EcoStruxure Power products unsafe deserializationhighCVSS 7.8EPSS 0.2%
- CVE-2026-6866: Schneider Electric EcoStruxure Panel Server insecure default credentialshighCVSS 7.5EPSS 0.3%
- CVE-2026-6332: Schneider Electric EcoStruxure Machine Expert HVAC cleartext storagehighCVSS 7.5EPSS 0.0%
- CVE-2025-6625: Schneider Electric Modicon M340 improper input validation in FTP servicehighCVSS 7.5
- CVE-2026-81861: CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information…highCVSS 6.5EPSS 0.5%
- CVE-2026-13336: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists…highCVSS 6.4EPSS 0.6%
- CVE-2026-13348: CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to…highCVSS 5.3EPSS 0.3%
- CVE-2026-1286: Schneider Electric EcoStruxure Foxboro DCS deserialization in project filesmediumCVSS 6.5EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 3 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 4 | 0 | |
| 7 Sep 2026 | 2 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/schneider-electric.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Schneider Electric vulnerabilities", https://junglewise.ai/threats/vendors/schneider-electric, 26 September 2026.