CVE-2026-4827: Schneider Electric Easergy c5
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.
Affected products
- Schneider Electric Easergy c5: up to and including 1.1.17
- Schneider Electric Easergy Micom c264: up to and including D7.33
- Schneider Electric Easergy Micom p30
- Schneider Electric Easergy Micom p40
- Schneider Electric Easylogic t150 Formerly Saitel Dr: up to and including 11.06.30
- Schneider Electric Ecostruxure Power Automation System Gateway Epas-Gtw: up to and including 6.4.616.200.100
- Schneider Electric Ecostruxure Power Automation System User Interface Epas-UI: up to and including 3.0.3
- Schneider Electric Ecostruxure Power Operation: up to and including 2022 CU6; up to and including 2024 CU2
- Schneider Electric Ipmfls: up to and including 64.2025.0.13
- Schneider Electric Powerlogic p5 Protection Relay: up to and including V02.502.103
- Schneider Electric Powerlogic p7 Protection And Control Platform: up to and including V02.002.002
- Schneider Electric Powerlogic t300: up to and including 2.9.4
- Schneider Electric Powerlogic t500: up to and including 11.08.02
- Schneider Electric Saitel Dp: up to and including 11.06.36
Published 2026-05-12. Last modified 2026-06-17.