Summary
- Schneider Electric's 8 September advisories cover several industrial and infrastructure product families.
- Newly disclosed flaws affect Modicon M580 controllers, PowerLogic T300 remote terminal units and SCADAPack x70 devices.
- The vulnerabilities span authentication, OS command injection and credential protection, creating different remediation demands across long-lived OT estates.
Schneider Electric has published a fresh set of industrial cybersecurity advisories covering weaknesses in programmable logic controllers, remote terminal units and other infrastructure-management products.
The disclosures issued on 8 September include an authentication flaw affecting Modicon M580 controllers, an operating-system command-injection vulnerability in PowerLogic T300 remote terminal units and insufficiently protected credentials across the SCADAPack x70 family.
CVE-2026-3869 affects Modicon M580 systems with application levels below 4.00 and Modicon M580 Safety systems below application level 4.20. Schneider classifies the weakness as an incorrect implementation of an authentication algorithm.
CVE-2026-77120 affects PowerLogic T300 RTUs at versions 2.9.8-5620 and earlier. Schneider describes the issue as improper neutralisation of special elements used in an operating-system command, creating a command-injection condition.
A third vulnerability, CVE-2026-81861, involves insufficiently protected credentials in SCADAPack x70 products. Schneider lists all versions of multiple SCADAPack 47x and 57x models as affected.
The company’s September security-notification release also covers two vulnerabilities in EcoStruxure IT Data Center Expert, involving server-side request forgery and argument injection, alongside updates to older Modicon security notices.
The range of affected products reflects a recurring difficulty in operational-technology vulnerability management. PLCs and RTUs can remain in production for much longer than conventional business applications, often as part of engineered systems in which firmware and configuration changes require testing, planned downtime and coordination with operational staff.
That makes the affected version number only the beginning of the remediation decision. Operators need to know where a vulnerable device is deployed, which functions are reachable and whether changes can be introduced without disrupting the physical process the equipment supports.
The security implications also differ between the flaws. An authentication weakness changes assumptions about who can reach protected functionality. An OS command-injection issue can create a path from application input into the underlying system. Poor credential protection raises questions about how long-lived secrets are stored and what other access they may unlock if exposed.
Those distinctions become particularly important in industrial estates where network boundaries are intended to compensate for the limited security capabilities of older equipment. A vulnerability that is difficult to exploit across a well-segmented control network can carry a different operational risk where engineering interfaces are exposed more broadly through enterprise connectivity or remote maintenance.
European operators face increasing pressure to demonstrate that such dependencies are being managed systematically. NIS2 has expanded cybersecurity risk-management expectations across many essential and important entities, while the Cyber Resilience Act is moving manufacturers towards stronger lifecycle obligations for products with digital elements.
Neither regime turns every newly published CVE into an incident, but both reinforce the need for accurate asset inventories, supplier vulnerability processes and evidence that remediation decisions are based on the real deployment environment.
Schneider’s public notifications reviewed for this article do not state that the three newly disclosed vulnerabilities are being exploited in the wild. The current issue is therefore one of exposure and remediation rather than a confirmed attack campaign.
The September batch nevertheless illustrates the breadth of the maintenance burden across industrial infrastructure. In a single release cycle, operators may need to assess authentication logic in controllers, command processing in remote terminal units and credential handling in equipment designed to remain operational for years.





