# Schneider EcoStruxure IT flaws enable RCE

Published: 2026-09-08 · Severity: routine · Sectors: infrastructure, manufacturing
Canonical: https://vorant.io/reports/c4085c91-76c9-5475-bbcb-20fe8cd13796/schneider-ecostruxure-it-flaws-enable-rce

> Schneider Electric EcoStruxure IT Data Center Expert before 9.1.2 has RCE and SSRF flaws fixed by the vendor; no exploitation reported.

ANSSI (CERT-FR) published an advisory covering multiple vulnerabilities in Schneider Electric's EcoStruxure IT Data Center Expert product, affecting versions prior to 9.1.2. The flaws, tracked as CVE-2026-19233 and CVE-2026-8044, allow an attacker to achieve remote arbitrary code execution and server-side request forgery (SSRF), respectively. These vulnerabilities were detailed in Schneider Electric's own security bulletin SEVD-2026-251-01, published on 8 September 2026.

The advisory does not indicate any evidence of active exploitation in the wild; it is a standard vendor-coordinated disclosure with patches available. Organizations using EcoStruxure IT Data Center Expert for data center infrastructure management should prioritize upgrading to version 9.1.2 or later, as SSRF and RCE vulnerabilities in data center management tools can pose significant risk to infrastructure and operational technology environments if left unpatched, given the typically privileged network position of such management software.

## Mentioned in this report

- Vulnerabilities: CVE-2026-19233, CVE-2026-8044

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1132

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c4085c91-76c9-5475-bbcb-20fe8cd13796/schneider-ecostruxure-it-flaws-enable-rce.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
