Schneider Electric patches weak-randomness flaw across dozens of grid control products

A session-management bug rated 8.3 affects protection relays, gateways and SCADA software used in power, water and chemical plants worldwide.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge photoreal close-up of an industrial serial-to-Ethernet device server mounted on a DIN rail inside a dimly lit network cabinet, blue and
Share

Key points

  • Schneider Electric has issued fixes for CVE-2026-4827, a weak-randomness flaw that could let an attacker hijack logged-in sessions on industrial control gear.
  • The bug carries a CVSS severity score of 8.3 out of 10 and affects Easergy, EcoStruxure, PowerLogic and Saitel product lines used in electricity, water and chemical plants.
  • Vulnerable kit includes MiCOM protection relays, EcoStruxure Power Operation SCADA software, and Easergy C5 bay controllers.
  • The advisory was published through CISA and lists fixed versions for most product families, with the P40 series flagged across all firmware.
  • Operators must contact Schneider's local Application Center to update devices, and a reboot is required.

Schneider Electric has pushed fixes for a vulnerability that runs through a huge swathe of its grid and substation gear, from small protection relays to full SCADA (the software that lets operators monitor and control a power system from a screen).

The flaw, tracked as CVE-2026-4827, is what engineers call insufficient entropy. In plain English: the products generate the secret numbers behind login sessions in a way that is too predictable. An attacker sitting on the same network can guess or replay those numbers and take over an authenticated session, then issue commands as if they were a real operator.

Severity is 8.3 out of 10. The advisory was published through CISA, the US Cybersecurity and Infrastructure Security Agency, as an update to earlier guidance.

What kit is affected?

A lot of it. The bug touches Easergy MiCOM protection relays, the MiCOM C264 and C434 bay controllers, EcoStruxure Power Automation Gateway and User Interface, EcoStruxure Power Operation (the on-premise SCADA), the iPMFLS load-shedding platform, PowerLogic P5 and P7 relays, PowerLogic T300 and T500 RTUs, Easergy C5, and Saitel DP and EasyLogic T150 RTUs.

The MiCOM P40 series is listed as vulnerable across all firmware versions where the Protocol Option bit is G, H or L. In practice that means some P40 units will need a hardware or configuration change, not just a firmware bump.

Product Vulnerable up to Fixed in
Easergy MiCOM C264 D7.33 D7.34
Easergy C5 1.1.17 1.1.18
EPAS-GTW 6.4.616.200.100 6.4.610.500.101
EcoStruxure Power Operation 2024 CU2 2024 CU3
PowerLogic P5 02.502.103 02.503.101
PowerLogic T300 2.9.4 2.9.5

Should the public worry?

Not directly, and not today. These are devices sitting inside substations, water treatment plants and industrial sites. You cannot reach them from the open internet in a properly run network. The failure mode here is an attacker who already has a foothold on the operational network, through a contractor laptop, a jump host, or a poorly segmented IT-to-OT link, then pivoting to grid controls.

That is not a theoretical scenario. It is the exact pattern seen in every serious ICS incident of the last decade.

How do operators fix it?

Unusually for a modern advisory, you cannot just click update. Schneider is routing patches through its Customer Care Center and local Application Centers, and every fix requires a device reboot. For a live protection relay, that means a planned outage window and coordination with the network operator.

One thing the post-mortem will say, if this ever gets exploited in anger, is that the patch existed for months and the change window never opened. That is the boring, real-world reason ICS bugs linger.

What should asset owners do now?

Inventory first. If you run any Easergy, EcoStruxure, PowerLogic or Saitel gear, pull firmware versions and match them against the advisory list. Then check network segmentation between corporate IT and the OT network, and audit who can reach the management interfaces of these devices. Session hijacking only matters if someone unauthorised can reach the login in the first place.

Operational takeaway: treat this as a segmentation audit with a patch attached, not a patch with a segmentation footnote.

© 2026 Threat Vectr