Schneider Electric patches three flaws in PowerLogic P7 grid protection gear

The most serious bug lets an unauthenticated attacker knock the device's control screen offline. A firmware update is out.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: an electrical substation control cabinet at dusk
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Schneider Electric disclosed three vulnerabilities in its PowerLogic P7 protection and control platform, used in electrical networks worldwide.
  • The highest-rated flaw, CVE-2026-9716, scores 7.5 out of 10 and can crash the device's control interface remotely without a login.
  • A second flaw, CVE-2026-9717, could let a logged-in attacker run commands with elevated privileges on the device.
  • Firmware version V02.004.001 fixes all three issues and is available from Schneider Electric's Customer Care Center.
  • Researchers at Cytrics found the vulnerabilities and reported them to Schneider Electric, whose CPCERT team passed them to CISA.

Schneider Electric has fixed three security bugs in the PowerLogic P7, a protection relay that sits inside electrical substations, watches current flowing through power lines and trips breakers when something goes wrong. The disclosure came through CISA, the US cybersecurity agency, which publishes advisories for industrial gear. The device is deployed in commercial and energy sites worldwide.

All three flaws affect PowerLogic P7 firmware version 0.2.003.001.000 and earlier.

What can an attacker actually do?

The worst of the three, tracked as CVE-2026-9716, is a null pointer dereference, a coding error that makes software crash when it receives unexpected input. Someone on the same network can send a malformed request that takes down the human-machine interface, the screen and controls operators use to configure the device. No password needed. The relay keeps protecting the circuit, but staff lose visibility and the ability to change settings until they reboot. Schneider rates it 7.5 out of 10.

The second bug, CVE-2026-9717, is a command injection flaw. An attacker who already holds a privileged login can smuggle operating-system commands into a request the device trusts, running them with high privileges. It touches confidentiality, integrity and availability. Rated 7.2.

The third, CVE-2026-9718, is a lower-severity denial-of-service issue that also requires an authenticated attacker. It scores 4.9.

All three sit on network services exposed on ports 8080 and 3702 and involve SOAP requests, a standard protocol for application-to-application communication, sent to a component called wsApp.

Is this being exploited?

There's no public evidence of exploitation. Cytrics reported the bugs privately to Schneider Electric through the normal coordinated disclosure route for industrial kit.

Neither Schneider nor CISA has attributed any activity to a specific group. Industrial protection relays have attracted state-linked attention before, including from the Sandworm cluster (Mandiant's naming) tied to Russia's GRU, which has repeatedly targeted Ukrainian electricity infrastructure. Nothing in this advisory connects the P7 bugs to that activity. Capability isn't intent.

What should operators do?

Schneider's fix is firmware version V02.004.001, available through the company's Customer Care Center. A reboot is required.

For sites that can't patch immediately, Schneider recommends restricting network access to ports 8080 and 3702, watching for unusual SOAP traffic aimed at wsApp and keeping administrative accounts tightly scoped so a stolen password doesn't hand an attacker the command-injection flaw.

We first covered the PowerLogic P7 on 3 July 2026; this disclosure confirms the device remains an active target for researcher scrutiny. The broader pattern here echoes what we reported in June on exposed automated tank gauges: authenticated-access bugs matter less than the unauthenticated one, but all three together map the full attack surface an operator needs to defend.

Ordinary utility customers don't need to act. This is work for the engineering teams that run substations.

© 2026 Threat Vectr