CVE-2026-35504: Subnet Solutions Powersystem Center 2020
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.
Affected products
- Subnet Solutions Powersystem Center 2020: before 5.29 (fixed in 5.29)
- Subnet Solutions Powersystem Center 2024: from 6.0, before 6.2 (fixed in 6.2)
- Subnet Solutions Powersystem Center 2026: from 7.0, before 7.1 (fixed in 7.1)
Published 2026-05-12. Last modified 2026-06-17.