# Schneider Electric PowerChute Serial Shutdown flaw patched

Published: 2026-09-17 · Severity: routine · Sectors: manufacturing, energy, technology, infrastructure
Canonical: https://vorant.io/reports/e44e7c86-b718-5a6c-8845-92dc892f255a/schneider-electric-powerchute-serial-shutdown-flaw-patched

> A brute-force authentication flaw in Schneider Electric PowerChute Serial Shutdown ≤1.5 lets attackers gain unauthorized account access; fixed in v1.6.

CISA republished a Schneider Electric CPCERT advisory (SEVD-2026-223-01) disclosing CVE-2026-13348, an Improper Restriction of Excessive Authentication Attempts (CWE-307) vulnerability in PowerChute Serial Shutdown, UPS management software used for graceful shutdown and energy management on desktops, servers and workstations. The flaw allows an attacker to perform an unlimited number of authentication attempts when redirect handling is disabled, potentially resulting in unauthorized access to a user account and, subsequently, disruption of operations or access to system data.

All versions 1.5 and prior are affected; version 1.6 fixes the issue and is available for both Windows and Linux. There is no indication of active exploitation in the wild; this is a vendor-driven vulnerability disclosure and patch release. Affected sectors per the advisory include Commercial Facilities, Critical Manufacturing, Energy, and Information Technology, with worldwide deployment. Defenders running PowerChute Serial Shutdown should upgrade to v1.6, verify the update via the Control Panel or About page, and apply standard ICS network segmentation and access-control best practices (isolating control networks, avoiding internet exposure, and using VPNs for remote access) as recommended by both Schneider Electric and CISA.

## Mentioned in this report

- Vulnerabilities: CVE-2026-13348

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-07

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e44e7c86-b718-5a6c-8845-92dc892f255a/schneider-electric-powerchute-serial-shutdown-flaw-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
