VORANT. Threat Intelligence Sign in Get the full feed

Schneider Electric IGSS Definition module out-of-bounds write flaw

medium vulnerability manufacturingenergy

A malicious CGF file can trigger an out-of-bounds write in Schneider Electric IGSS Definition module, risking data loss or code execution.

CISA republished a Schneider Electric advisory (SEVD-2026-195-01) disclosing CVE-2026-12927, an out-of-bounds write vulnerability (CWE-787) in the IGSS Definition module (Def.exe), a design-time component of the IGSS SCADA platform used by system integrators to build mimic diagrams. The flaw is triggered when a specially crafted CGF file is imported, potentially leading to loss of data or arbitrary code execution and, by extension, loss of control over the SCADA environment.

Affected versions include IGSS Definition module up to and including 18.0.0.26124, with 18.0.0.26125 confirmed vulnerable as well per the version range listed. Schneider Electric has released version 18.0.0.26125 as the fixed build, distributed via IGSS Master's Update IGSS Software feature or direct download. No exploitation in the wild has been reported; the vulnerability was responsibly disclosed to CISA by Schneider Electric and independent researcher Michael Heinzl. IGSS is deployed worldwide across Commercial Facilities, Critical Manufacturing, and Energy sectors, making unpatched Definition modules a supply-chain-style risk point for engineering workstations feeding production SCADA systems.

Until patched, CISA and Schneider Electric recommend avoiding execution of commands or opening/importing files (including CGF files) from untrusted sources, alongside standard ICS network segmentation, firewalling, and VPN best practices for any remote access. This is a routine, disclosed-not-exploited advisory typical of ICS engineering-tool vulnerabilities.

Mentioned in this report

Vulnerabilities CVE-2026-12927

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free