CVE Tools

Schneider-electric

548 CVEs tracked since 2011. Since Apr 2013, 3 of them reached CISA KEV.

Schneider-electric CVEs per month

Apr 2013 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Schneider-electric CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2013-0440
2013-05null or fewer
2013-06null or fewer
2013-07null or fewer
2013-0810
2013-09null or fewer
2013-10null or fewer
2013-11null or fewer
2013-12null or fewer
2014-01null or fewer
2014-0230
2014-0320
2014-04null or fewer
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-0850
2014-0940
2014-10null or fewer
2014-11null or fewer
2014-1240
2015-0130
2015-0210
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-1210
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-0730
2017-08null or fewer
2017-0970
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-0730
2018-0850
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12120
2019-01null or fewer
2019-0250
2019-03null or fewer
2019-04null or fewer
2019-05421
2019-06null or fewer
2019-0750
2019-08null or fewer
2019-0990
2019-10100
2019-1130
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-0350
2020-04null or fewer
2020-05null or fewer
2020-06170
2020-07null or fewer
2020-0850
2020-09null or fewer
2020-10null or fewer
2020-11230
2020-12140
2021-0130
2021-02null or fewer
2021-03null or fewer
2021-0450
2021-05120
2021-06null or fewer
2021-07160
2021-08190
2021-0940
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-0160
2022-02260
2022-03160
2022-0470
2022-05null or fewer
2022-06100
2022-07120
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-1180
2022-12null or fewer
2023-01280
2023-0290
2023-03null or fewer
2023-04240
2023-05170
2023-0640
2023-0760
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-1150
2023-12null or fewer
2024-01null or fewer
2024-0240
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06130
2024-0760
2024-08null or fewer
2024-09null or fewer
2024-1080
2024-1170
2024-12null or fewer
2025-0190
2025-0290
2025-03null or fewer
2025-0461
2025-05null or fewer
2025-06100
2025-0770
2025-08100
2025-09null or fewer
2025-1051
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-0480
2026-05null or fewer
2026-06null or fewer
2026-07null or fewer
2026-08null or fewer
2026-0990

Products

The products that kept showing up in Schneider-electric's monthly top three, with their CVEs summed over those months.

  1. Modicon Quantum232 months
  2. Modicon Quantum Safety Controller222 months
  3. Plc Simulator222 months
  4. Ecostruxure Control Expert204 months
  5. Interactive Graphical Scada System183 months
  6. Hmiscu151 month
  7. Modicon LMC058151 month
  8. Modicon M262151 month
  9. Ecostruxure Process Expert132 months
  10. Struxureware Data Center Expert132 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Schneider-electric.

  1. CVE-2026-3869CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project w...—
  2. CVE-2026-81861CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.6.5
  3. CVE-2026-77120CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause privilege escalation to root and unauthorized execution of a...—
  4. CVE-2026-19233CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends craft...—
  5. CVE-2026-8044CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when ...—
  6. CVE-2026-13348CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number ...5.3
  7. CVE-2026-13337CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-s...6.4
  8. CVE-2026-13336CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands when a system b...6.4
  9. CVE-2024-10085CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large number of OPC UA reques...7.5
  10. CVE-2026-12927CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition.7.8
  11. CVE-2026-0667CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating o...9.8
  12. CVE-2026-14354CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devic...—
  13. CVE-2026-9718CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request ...6.5
  14. CVE-2026-9717CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting...7.2
  15. CVE-2026-9716CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed request...7.5

The record

Peak rank
#6 in May 2019
Busiest month shown
May 2019, 42 CVEs
Months with a KEV entry
3 since Apr 2013
Monthly snapshots
62 since 2011
Schneider-electric's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store