# Schneider Electric SCADAPack RTUs credential flaw

Published: 2026-09-15 · Severity: routine · Sectors: manufacturing, energy
Canonical: https://vorant.io/reports/8cb5e32e-1d8e-5379-9a0b-68497324ea01/schneider-electric-scadapack-rtus-credential-flaw

> CISA/Schneider advisory warns SCADAPack x70 and 3xx series RTUs expose credentials via legacy Secure Lock, risking unauthorized access to device configuration.

CISA republished a Schneider Electric CPCERT advisory (SEVD-2026-251-03) describing an insufficiently protected credentials vulnerability (CVE-2026-81861, CWE-522) affecting SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32 Remote Terminal Unit (RTU) product lines, used across critical manufacturing and energy sectors worldwide. The flaw resides in the legacy Secure Lock functionality and could allow unauthorized access to RTU configuration, resulting in loss of confidentiality of authentication information and RTU functionality.

No evidence of active exploitation is indicated in the advisory. Schneider Electric recommends migrating from the legacy Secure Lock feature to Role-Based Access Control (RBAC), which is the recommended access control mechanism for these devices. Additional mitigations include network segmentation between trusted and untrusted networks, enabling the RTU firewall service, following the SCADAPack Cybersecurity Guide (hardening and secured communication sections), and standard ICS best practices such as isolating control networks from business networks and internet, using VPNs for remote access, and physical access controls. The vulnerability was reported to CISA by researcher Abhinav Agarwal.

## Mentioned in this report

- Vulnerabilities: CVE-2026-81861

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-04

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8cb5e32e-1d8e-5379-9a0b-68497324ea01/schneider-electric-scadapack-rtus-credential-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
