CVE-2026-2401: Schneider Electric Powerchute Serial Shutdown

Medium severity, CVSS 5.0. EPSS: 0.1% chance of exploitation in the next 30 days.

CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker.

Affected products

Published 2026-04-14. Last modified 2026-06-17.