Schneider EcoStruxure Admin Expert security bypass flaw
A vulnerability in Schneider Electric EcoStruxure Cybersecurity Admin Expert (≤4.2.0) allows an attacker to bypass security policy enforcement.
ANSSI (CERT-FR) issued an advisory covering a vulnerability in Schneider Electric's EcoStruxure Cybersecurity Admin Expert, affecting all versions up to and including 4.2.0. The flaw, tracked as CVE-2026-14354, allows an attacker to circumvent the product's security policy controls, which could undermine centralized security management for industrial environments relying on this tool.
Schneider Electric published a corresponding security bulletin (SEVD-2026-195-02) on July 14, 2026, detailing the issue and providing remediation guidance. Organizations using affected versions of EcoStruxure Cybersecurity Admin Expert should apply the vendor's patches or mitigations promptly, as this product is typically deployed in operational technology and critical infrastructure settings where security policy integrity is essential.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0881
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free