CVE-2026-1226: Schneider Electric Ecostruxure Building Operation Webstation

High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.

CWE‑94: Improper Control of Generation of Code vulnerability exists that could cause execution of untrusted or unintended code within the application when maliciously crafted design content is processed through a TGML graphics file.

Affected products

Published 2026-02-11. Last modified 2026-06-17.