VORANT. Threat Intelligence Sign in Get the full feed

Schneider Electric PowerChute Serial Shutdown flaws patched

medium vulnerability energyhealthcaretechnologytransportationtelecommunications

Schneider Electric patched seven vulnerabilities in PowerChute Serial Shutdown that could let attackers overwrite files, forge logs, or cause denial of service; fixed in v1.5.

CISA and Schneider Electric disclosed seven vulnerabilities affecting PowerChute Serial Shutdown versions 1.4 and earlier, a UPS management tool deployed worldwide across critical manufacturing, energy, healthcare, IT, transportation, and communications sectors. The flaws span path traversal (CWE-22), improper output encoding enabling log injection (CWE-116), insufficient brute-force protection (CWE-307), uncontrolled resource consumption (CWE-400), improper quantity validation causing log truncation (CWE-1284), CRLF injection allowing configuration tampering (CWE-93), and insertion of sensitive information into log files (CWE-532).

Successful exploitation could allow an attacker to overwrite critical system files, forge or inject malicious log entries, bypass account lockout protections, trigger denial-of-service conditions, truncate audit logs to reduce visibility, tamper with configuration data via CRLF sequences, or expose sensitive information through logging. These issues affect deployments on Windows, Red Hat Enterprise Linux, and SuSE Linux. Schneider Electric reported the vulnerabilities to CISA and released version 1.5 to remediate all seven CVEs.

No public exploitation has been reported at this time. CISA recommends standard ICS hardening practices — minimizing network exposure, isolating control system networks behind firewalls, and using VPNs for remote access — in addition to applying the vendor's version 1.5 update.

Mentioned in this report

Vulnerabilities CVE-2026-2399CVE-2026-2400CVE-2026-2401CVE-2026-2402CVE-2026-2403CVE-2026-2404CVE-2026-2405

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-02

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free