Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical CVE‑2026‑0667 in Schneider Electric SCADAPack RTUs Enables Remote Code Execution, Threatening Energy Sector OT

Schneider Electric disclosed CVE‑2026‑0667, a critical flaw in its SCADAPack and RemoteConnect devices that permits unauthenticated remote code execution over Modbus TCP. The vulnerability affects widely deployed RTUs in the energy sector, creating a supply‑chain risk for utilities and their service providers.

LiveThreat™ Intelligence · 📅 March 17, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
5 recommended
📰
Source
cisa.gov

Critical CVE‑2026‑0667 in Schneider Electric SCADAPack & RemoteConnect RTUs Enables Remote Code Execution

What It Is – Schneider Electric disclosed a critical vulnerability (CVE‑2026‑0667) in its SCADAPack x70 series Remote Terminal Units (RTUs) and RemoteConnect gateway. The flaw is an improper check for unusual conditions in the Modbus TCP stack, allowing an unauthenticated attacker to execute arbitrary code, cause denial‑of‑service, and compromise confidentiality and integrity of the controller.

Exploitability – The vulnerability scores 9.8 (CVSS v3.1), indicating a high likelihood of remote exploitation. Proof‑of‑concept code has been shared publicly, and threat actors are actively scanning for vulnerable devices in the wild.

Affected Products –

  • Schneider Electric SCADAPack 47xi, 47x, 57x (firmware < 9.12.2)
  • Schneider Electric RemoteConnect gateway (generic version)

TPRM Impact – OT devices that sit in the supply chain of energy utilities, industrial automation integrators, and managed service providers become a direct entry point for attackers. Compromise can cascade to downstream customers, disrupt power distribution, and expose critical process data.

Recommended Actions –

  • Patch immediately – Upgrade SCADAPack firmware to 9.12.2 or later and apply the latest RemoteConnect update.
  • Network segmentation – Isolate RTUs on dedicated VLANs and restrict Modbus TCP traffic to trusted sources only.
  • Access hardening – Enforce strong authentication, disable default credentials, and implement role‑based access controls.
  • Monitoring – Deploy IDS/IPS signatures for Modbus anomalies and enable logging of all RTU communications.
  • Supply‑chain review – Verify that any third‑party integrators or MSPs managing these devices have applied the remediation.

Source: CISA Advisory – ICSA‑26‑076‑02

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-02 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →