CVE-2026-2273: Schneider Electric Ecostruxure Automation Expert

High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.

CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent system when an authenticated user opens a malicious project file.

Affected products

Published 2026-03-10. Last modified 2026-06-23.