VORANT. Threat Intelligence Sign in Get the full feed

Schneider Electric power products vulnerable to session hijacking

high vulnerability energyinfrastructuremanufacturing

A session-management flaw in dozens of Schneider Electric ICS products could allow network attackers to hijack sessions and access operational data; patches are available for most affected devices.

Schneider Electric has disclosed CVE-2026-4827, an insufficient-entropy vulnerability affecting session management in a wide range of its industrial control system products, including the Easergy MiCOM relay series, EcoStruxure Power Operation platforms, and PowerLogic protection and metering devices. The flaw could allow a network-positioned attacker to exploit weak session-management protections to gain unauthorized access and potentially disrupt operations or access system data. The vulnerability affects critical infrastructure sectors including energy, water, chemical, and manufacturing facilities worldwide.

Schneider Electric has released firmware updates for most affected product lines, including MiCOM C264, P139, P439, P539, P632-634, PowerLogic T300/T500/P5/P7, EcoStruxure Power Operation 2022/2024, and others. Some product lines—specifically certain MiCOM P30 and P40 series models—do not yet have patches available. For these and for organizations unable to immediately patch, Schneider Electric recommends network segmentation, firewall controls, intrusion detection, and reducing session timeout periods via the CAE configuration tool.

The advisory affects energy and industrial automation systems deployed globally. While the vulnerability requires network access and is not remotely exploitable from the internet if standard ICS segmentation practices are followed, successful exploitation could compromise protective relay systems and power automation infrastructure. Organizations should prioritize patching internet-facing or inadequately segmented OT networks and review session timeout configurations as an interim control.

Mentioned in this report

Vulnerabilities CVE-2026-4827

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-07

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free