VORANT. Threat Intelligence Sign in Get the full feed

Schneider EcoStruxure IT flaws enable RCE

routine vulnerability infrastructuremanufacturing

Schneider Electric EcoStruxure IT Data Center Expert before 9.1.2 has RCE and SSRF flaws fixed by the vendor; no exploitation reported.

ANSSI (CERT-FR) published an advisory covering multiple vulnerabilities in Schneider Electric's EcoStruxure IT Data Center Expert product, affecting versions prior to 9.1.2. The flaws, tracked as CVE-2026-19233 and CVE-2026-8044, allow an attacker to achieve remote arbitrary code execution and server-side request forgery (SSRF), respectively. These vulnerabilities were detailed in Schneider Electric's own security bulletin SEVD-2026-251-01, published on 8 September 2026.

The advisory does not indicate any evidence of active exploitation in the wild; it is a standard vendor-coordinated disclosure with patches available. Organizations using EcoStruxure IT Data Center Expert for data center infrastructure management should prioritize upgrading to version 9.1.2 or later, as SSRF and RCE vulnerabilities in data center management tools can pose significant risk to infrastructure and operational technology environments if left unpatched, given the typically privileged network position of such management software.

Mentioned in this report

Vulnerabilities CVE-2026-19233CVE-2026-8044

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1132

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free