CVE-2026-14354: Schneider Electric Ecostruxure Cybersecurity Admin Expert

High severity, CVSS 8.7. EPSS: 0.2% chance of exploitation in the next 30 days.

CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker leverages weaknesses in the handling and protection of stored credentials within the application.

Affected products

Published 2026-07-29. Last modified 2026-07-30.