mediumOther

Schneider Electric PowerChute Serial Shutdown Multiple Vulnerabilities

First seen Jul 10, 2026 · Updated Jul 10, 2026 · CVSS 6.1

ICSSCADAschneider-electricpath-traversalcrlf-injectionlog-injectionauthentication-bypassdenial-of-serviceindustrial-control-systemsCISA-advisory

Schneider Electric PowerChute Serial Shutdown versions 1.4 and earlier contain seven distinct vulnerabilities spanning path traversal, CRLF injection, weak authentication throttling, uncontrolled resource consumption, and sensitive information logging. Successful exploitation could allow attackers to overwrite critical files, forge log data, exhaust system resources, or expose sensitive information, though no public exploitation has been reported. Schneider Electric has released version 1.5 to remediate all identified issues.

Technical Analysis

The advisory covers seven CVEs (CVE-2026-2399 through CVE-2026-2405) affecting PowerChute Serial Shutdown <=1.4 across Windows, Red Hat, and SuSE Linux platforms. Key issues include CWE-22 path traversal (CVE-2026-2399, CVSS 6.1) allowing overwrite of critical system files, CWE-93 CRLF injection (CVE-2026-2400) enabling configuration data tampering, CWE-307 insufficient authentication attempt limiting (CVE-2026-2402) across multiple endpoints, and CWE-532 insertion of sensitive information into log files (CVE-2026-2401). Attack vectors range from adjacent-network (AV:A) requiring high privileges for the path traversal flaw, to network-accessible (AV:N) low-complexity issues for several others, with no CVE currently rated above medium severity. PowerChute is UPS management software typically deployed on servers and infrastructure hosts to trigger graceful shutdowns during power events; if such hosts also run AI agent orchestration, RAG pipelines, or LLM inference workloads, log injection or credential-adjacent exposure (CVE-2026-2401, CVE-2026-2403) could corrupt audit trails or leak secrets that agents rely on for authentication, and unplanned shutdowns triggered via DoS (CVE-2026-2405) could interrupt agent task continuity.

Affected Systems

Schneider Electric PowerChute Serial Shutdown version 1.4 and prior, installed on Microsoft Windows, Red Hat Enterprise Linux, and SuSE Linux Enterprise Server.

Indicators of Compromise

  • No specific IOCs published; this is a vulnerability disclosure rather than an active campaign.
  • Advisory reference: ICSA-26-190-02
  • Vendor advisory: SEVD-2026-104-01

Remediation Steps

  1. 1

    Upgrade to PowerChute Serial Shutdown 1.5

    Download and install version 1.5 for Windows or Linux from Schneider Electric's official download portal, which remediates all seven CVEs (CVE-2026-2399 to CVE-2026-2405).

  2. 2

    Apply vendor hardening guidance

    Follow the PowerChute Security Handbook (SPD_CCON-PCSSSH_EN) for additional configuration hardening and mitigation instructions.

  3. 3

    Restrict network exposure

    Ensure PowerChute and other ICS/OT management systems are not internet-accessible; isolate them behind firewalls and segment from business networks.

  4. 4

    Use secure remote access

    If remote management is required, use VPNs kept current with security patches rather than direct exposure.

  5. 5

    Audit and protect log files

    Review logs for potentially injected sensitive data or CRLF-based tampering, and restrict access to log storage locations given the log injection and sensitive information disclosure risks.

  6. 6

    Monitor authentication endpoints

    Implement external rate-limiting or account lockout controls to compensate for insufficient built-in authentication attempt restrictions until upgraded.

CVE / Advisory IDs

CVE-2026-2399CVE-2026-2400CVE-2026-2401CVE-2026-2402CVE-2026-2403CVE-2026-2404CVE-2026-2405

Industries Most Exposed

CommunicationsCritical ManufacturingEnergyHealthcare and Public HealthInformation TechnologyTransportation Systems

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.