{"schema_version":1,"title":"Schneider Electric vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 27 vulnerabilities in Schneider Electric: 0 in the last 7 days and 10 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-6625, was published on 17 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/schneider-electric","json_url":"https://junglewise.ai/threats/vendors/schneider-electric.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/schneider-electric","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":9,"all_time":27,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":7,"last_90_days":10,"last_365_days":27},"latest":[{"cve":"CVE-2025-6625","cvss":7.5,"slug":"cve-2025-6625-schneider-electric-modicon-m340-improper-input-validation-in-ftp","title":"Schneider Electric Modicon M340 improper input validation in FTP service","severity":"high","exploited":false,"published_at":"2026-09-17T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-6625-schneider-electric-modicon-m340-improper-input-validation-in-ftp"},{"cve":"CVE-2026-81861","cvss":6.5,"epss":0.0054,"slug":"cve-2026-81861-schneider-electric-scadapack-x70-insufficiently-protected","title":"CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized acc","severity":"high","exploited":false,"published_at":"2026-09-11T16:17:47.613+00:00","url":"https://junglewise.ai/threats/cve-2026-81861-schneider-electric-scadapack-x70-insufficiently-protected"},{"cve":"CVE-2026-3869","epss":0.0054,"slug":"cve-2026-3869-schneider-electric-plc-authentication-algorithm-incorrect","title":"Schneider Electric PLC authentication algorithm incorrect implementation","severity":"info","exploited":false,"published_at":"2026-09-11T16:17:06.2+00:00","url":"https://junglewise.ai/threats/cve-2026-3869-schneider-electric-plc-authentication-algorithm-incorrect"},{"cve":"CVE-2026-13348","cvss":5.3,"epss":0.0031,"slug":"cve-2026-13348-schneider-electric-powerchute-serial-shutdown-improper","title":"CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized ac","severity":"high","exploited":false,"published_at":"2026-09-01T14:17:24.703+00:00","url":"https://junglewise.ai/threats/cve-2026-13348-schneider-electric-powerchute-serial-shutdown-improper"},{"cve":"CVE-2026-13337","epss":0.0018,"slug":"cve-2026-13337-schneider-electric-netbotz-sql-injection-in-hibernate-query","title":"Schneider Electric NetBotz SQL injection in Hibernate query interface","severity":"info","exploited":false,"published_at":"2026-09-01T14:17:24.563+00:00","url":"https://junglewise.ai/threats/cve-2026-13337-schneider-electric-netbotz-sql-injection-in-hibernate-query"},{"cve":"CVE-2026-13336","cvss":6.4,"epss":0.006,"slug":"cve-2026-13336-schneider-electric-netbotz-5-750-755-os-command-injection-and-sql","title":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause exe","severity":"high","exploited":false,"published_at":"2026-09-01T14:17:24.43+00:00","url":"https://junglewise.ai/threats/cve-2026-13336-schneider-electric-netbotz-5-750-755-os-command-injection-and-sql"},{"cve":"CVE-2024-10085","epss":0.0032,"slug":"cve-2024-10085-schneider-electric-opc-ua-resource-exhaustion-denial-of-service","title":"Schneider Electric OPC UA resource exhaustion denial of service","severity":"info","exploited":false,"published_at":"2026-09-01T14:17:22.62+00:00","url":"https://junglewise.ai/threats/cve-2024-10085-schneider-electric-opc-ua-resource-exhaustion-denial-of-service"},{"cve":"CVE-2026-14354","cvss":8.7,"slug":"cve-2026-14354-schneider-electric-ecostruxure-cybersecurity-admin-expert","title":"Schneider Electric EcoStruxure Cybersecurity Admin Expert credential protection bypass","severity":"info","exploited":false,"published_at":"2026-07-29T13:17:42.723+00:00","url":"https://junglewise.ai/threats/cve-2026-14354-schneider-electric-ecostruxure-cybersecurity-admin-expert"},{"cve":"CVE-2026-12927","cvss":8.4,"slug":"cve-2026-12927-schneider-electric-igss-definition-out-of-bounds-write-via-cgf","title":"Schneider Electric IGSS Definition out-of-bounds write via CGF import","severity":"info","exploited":false,"published_at":"2026-07-29T13:17:36.3+00:00","url":"https://junglewise.ai/threats/cve-2026-12927-schneider-electric-igss-definition-out-of-bounds-write-via-cgf"},{"cve":"CVE-2026-0667","cvss":9.3,"slug":"cve-2026-0667-schneider-electric-scadapack-code-execution-in-modbus-tcp-protocol","title":"Schneider Electric SCADAPack code execution in Modbus TCP protocol handling","severity":"info","exploited":false,"published_at":"2026-07-29T13:17:29.18+00:00","url":"https://junglewise.ai/threats/cve-2026-0667-schneider-electric-scadapack-code-execution-in-modbus-tcp-protocol"},{"cve":"CVE-2026-9718","cvss":6.9,"slug":"cve-2026-9718-schneider-electric-powerlogic-p7-reachable-assertion-in-network","title":"Schneider Electric PowerLogic P7 reachable assertion in network service","severity":"info","exploited":false,"published_at":"2026-06-25T16:16:44.33+00:00","url":"https://junglewise.ai/threats/cve-2026-9718-schneider-electric-powerlogic-p7-reachable-assertion-in-network"},{"cve":"CVE-2026-9717","cvss":8.6,"slug":"cve-2026-9717-schneider-electric-powerlogic-p7-os-command-injection","title":"Schneider Electric PowerLogic P7 OS command injection","severity":"info","exploited":false,"published_at":"2026-06-25T16:16:44.22+00:00","url":"https://junglewise.ai/threats/cve-2026-9717-schneider-electric-powerlogic-p7-os-command-injection"},{"cve":"CVE-2026-9716","cvss":8.7,"slug":"cve-2026-9716-schneider-electric-powerlogic-p7-null-pointer-dereference-dos","title":"Schneider Electric PowerLogic P7 NULL pointer dereference DoS","severity":"info","exploited":false,"published_at":"2026-06-25T16:16:44.107+00:00","url":"https://junglewise.ai/threats/cve-2026-9716-schneider-electric-powerlogic-p7-null-pointer-dereference-dos"},{"cve":"CVE-2026-9651","cvss":6.7,"slug":"cve-2026-9651-schneider-electric-rtu-incorrect-permission-assignment-in-system","title":"Schneider Electric RTU incorrect permission assignment in system files","severity":"info","exploited":false,"published_at":"2026-06-25T16:16:43.99+00:00","url":"https://junglewise.ai/threats/cve-2026-9651-schneider-electric-rtu-incorrect-permission-assignment-in-system"},{"cve":"CVE-2026-9650","cvss":8.7,"slug":"cve-2026-9650-schneider-electric-easylogic-and-saitel-rtu-unprotected","title":"Schneider Electric EasyLogic and Saitel RTU unprotected credentials","severity":"info","exploited":false,"published_at":"2026-06-25T16:16:43.867+00:00","url":"https://junglewise.ai/threats/cve-2026-9650-schneider-electric-easylogic-and-saitel-rtu-unprotected"},{"cve":"CVE-2026-8045","cvss":7.1,"slug":"cve-2026-8045-schneider-electric-data-center-expert-xxe-in-soap-service","title":"Schneider Electric Data Center Expert XXE in SOAP service","severity":"info","exploited":false,"published_at":"2026-06-09T16:16:44.453+00:00","url":"https://junglewise.ai/threats/cve-2026-8045-schneider-electric-data-center-expert-xxe-in-soap-service"},{"cve":"CVE-2026-6332","cvss":7.5,"epss":0.0001,"slug":"cve-2026-6332-schneider-electric-ecostruxure-machine-expert-hvac-cleartext","title":"Schneider Electric EcoStruxure Machine Expert HVAC cleartext storage","severity":"high","exploited":false,"published_at":"2026-05-14T18:16:51.067+00:00","url":"https://junglewise.ai/threats/cve-2026-6332-schneider-electric-ecostruxure-machine-expert-hvac-cleartext"},{"cve":"CVE-2026-6866","cvss":7.5,"epss":0.003,"slug":"cve-2026-6866-schneider-electric-ecostruxure-panel-server-insecure-default","title":"Schneider Electric EcoStruxure Panel Server insecure default credentials","severity":"high","exploited":false,"published_at":"2026-05-12T15:16:16.57+00:00","url":"https://junglewise.ai/threats/cve-2026-6866-schneider-electric-ecostruxure-panel-server-insecure-default"},{"cve":"CVE-2026-6865","cvss":7.1,"slug":"cve-2026-6865-schneider-electric-path-traversal-in-server-side-file-processing","title":"Schneider Electric path traversal in server-side file processing","severity":"info","exploited":false,"published_at":"2026-05-12T14:17:10.567+00:00","url":"https://junglewise.ai/threats/cve-2026-6865-schneider-electric-path-traversal-in-server-side-file-processing"},{"cve":"CVE-2026-4827","cvss":8.7,"slug":"cve-2026-4827-schneider-electric-products-insufficient-entropy-in-session","title":"Schneider Electric products insufficient entropy in session management","severity":"info","exploited":false,"published_at":"2026-05-12T13:17:35.51+00:00","url":"https://junglewise.ai/threats/cve-2026-4827-schneider-electric-products-insufficient-entropy-in-session"},{"cve":"CVE-2026-2273","cvss":8.2,"epss":0.0022,"slug":"cve-2026-2273-schneider-electric-ecostruxure-automation-expert-code-injection","title":"Schneider Electric EcoStruxure Automation Expert code injection","severity":"high","exploited":false,"published_at":"2026-03-10T18:18:48.007+00:00","url":"https://junglewise.ai/threats/cve-2026-2273-schneider-electric-ecostruxure-automation-expert-code-injection"},{"cve":"CVE-2026-1286","cvss":6.5,"epss":0.0033,"slug":"cve-2026-1286-schneider-electric-ecostruxure-foxboro-dcs-deserialization-in","title":"Schneider Electric EcoStruxure Foxboro DCS deserialization in project files","severity":"medium","exploited":false,"published_at":"2026-03-10T18:18:04.917+00:00","url":"https://junglewise.ai/threats/cve-2026-1286-schneider-electric-ecostruxure-foxboro-dcs-deserialization-in"},{"cve":"CVE-2025-13902","cvss":5.4,"epss":0.0039,"slug":"cve-2025-13902-schneider-electric-modicon-controllers-xss-in-web-server","title":"Schneider Electric Modicon Controllers XSS in Web Server","severity":"medium","exploited":false,"published_at":"2026-03-10T18:17:52.223+00:00","url":"https://junglewise.ai/threats/cve-2025-13902-schneider-electric-modicon-controllers-xss-in-web-server"},{"cve":"CVE-2025-13901","cvss":5.3,"epss":0.0048,"slug":"cve-2025-13901-schneider-electric-modicon-dos-in-machine-expert-protocol","title":"Schneider Electric Modicon DoS in Machine Expert protocol","severity":"medium","exploited":false,"published_at":"2026-03-10T18:17:52.063+00:00","url":"https://junglewise.ai/threats/cve-2025-13901-schneider-electric-modicon-dos-in-machine-expert-protocol"},{"cve":"CVE-2025-11739","cvss":7.8,"epss":0.0019,"slug":"cve-2025-11739-schneider-electric-ecostruxure-power-products-unsafe","title":"Schneider Electric EcoStruxure Power products unsafe deserialization","severity":"high","exploited":false,"published_at":"2026-03-10T18:17:51.88+00:00","url":"https://junglewise.ai/threats/cve-2025-11739-schneider-electric-ecostruxure-power-products-unsafe"}],"vendor":{"hub":true,"name":"Schneider Electric","slug":"schneider-electric","homepage":"https://www.se.com/","description":"A multinational company specializing in energy management and industrial automation.","url":"https://junglewise.ai/threats/vendors/schneider-electric"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-2273","cvss":8.2,"epss":0.0022,"slug":"cve-2026-2273-schneider-electric-ecostruxure-automation-expert-code-injection","title":"Schneider Electric EcoStruxure Automation Expert code injection","severity":"high","exploited":false,"published_at":"2026-03-10T18:18:48.007+00:00","url":"https://junglewise.ai/threats/cve-2026-2273-schneider-electric-ecostruxure-automation-expert-code-injection"},{"cve":"CVE-2025-13845","cvss":7.8,"epss":0.0035,"slug":"cve-2025-13845-schneider-electric-rapsody-use-after-free-in-project-file-parsing","title":"Schneider Electric Rapsody use-after-free in project file parsing","severity":"high","exploited":false,"published_at":"2026-01-15T19:16:02.937+00:00","url":"https://junglewise.ai/threats/cve-2025-13845-schneider-electric-rapsody-use-after-free-in-project-file-parsing"},{"cve":"CVE-2025-11739","cvss":7.8,"epss":0.0019,"slug":"cve-2025-11739-schneider-electric-ecostruxure-power-products-unsafe","title":"Schneider Electric EcoStruxure Power products unsafe deserialization","severity":"high","exploited":false,"published_at":"2026-03-10T18:17:51.88+00:00","url":"https://junglewise.ai/threats/cve-2025-11739-schneider-electric-ecostruxure-power-products-unsafe"},{"cve":"CVE-2026-6866","cvss":7.5,"epss":0.003,"slug":"cve-2026-6866-schneider-electric-ecostruxure-panel-server-insecure-default","title":"Schneider Electric EcoStruxure Panel Server insecure default credentials","severity":"high","exploited":false,"published_at":"2026-05-12T15:16:16.57+00:00","url":"https://junglewise.ai/threats/cve-2026-6866-schneider-electric-ecostruxure-panel-server-insecure-default"},{"cve":"CVE-2026-6332","cvss":7.5,"epss":0.0001,"slug":"cve-2026-6332-schneider-electric-ecostruxure-machine-expert-hvac-cleartext","title":"Schneider Electric EcoStruxure Machine Expert HVAC cleartext storage","severity":"high","exploited":false,"published_at":"2026-05-14T18:16:51.067+00:00","url":"https://junglewise.ai/threats/cve-2026-6332-schneider-electric-ecostruxure-machine-expert-hvac-cleartext"},{"cve":"CVE-2025-6625","cvss":7.5,"slug":"cve-2025-6625-schneider-electric-modicon-m340-improper-input-validation-in-ftp","title":"Schneider Electric Modicon M340 improper input validation in FTP service","severity":"high","exploited":false,"published_at":"2026-09-17T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-6625-schneider-electric-modicon-m340-improper-input-validation-in-ftp"},{"cve":"CVE-2026-81861","cvss":6.5,"epss":0.0054,"slug":"cve-2026-81861-schneider-electric-scadapack-x70-insufficiently-protected","title":"CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized acc","severity":"high","exploited":false,"published_at":"2026-09-11T16:17:47.613+00:00","url":"https://junglewise.ai/threats/cve-2026-81861-schneider-electric-scadapack-x70-insufficiently-protected"},{"cve":"CVE-2026-13336","cvss":6.4,"epss":0.006,"slug":"cve-2026-13336-schneider-electric-netbotz-5-750-755-os-command-injection-and-sql","title":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause exe","severity":"high","exploited":false,"published_at":"2026-09-01T14:17:24.43+00:00","url":"https://junglewise.ai/threats/cve-2026-13336-schneider-electric-netbotz-5-750-755-os-command-injection-and-sql"},{"cve":"CVE-2026-13348","cvss":5.3,"epss":0.0031,"slug":"cve-2026-13348-schneider-electric-powerchute-serial-shutdown-improper","title":"CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized ac","severity":"high","exploited":false,"published_at":"2026-09-01T14:17:24.703+00:00","url":"https://junglewise.ai/threats/cve-2026-13348-schneider-electric-powerchute-serial-shutdown-improper"},{"cve":"CVE-2026-1286","cvss":6.5,"epss":0.0033,"slug":"cve-2026-1286-schneider-electric-ecostruxure-foxboro-dcs-deserialization-in","title":"Schneider Electric EcoStruxure Foxboro DCS deserialization in project files","severity":"medium","exploited":false,"published_at":"2026-03-10T18:18:04.917+00:00","url":"https://junglewise.ai/threats/cve-2026-1286-schneider-electric-ecostruxure-foxboro-dcs-deserialization-in"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Schneider Electric PowerLogic P7","slug":"powerlogic-p7","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/powerlogic-p7"}]}