PatchSiren cyber security CVE debrief
CVE-2026-0667 Schneider Electric CVE debrief
Schneider Electric and CISA describe CVE-2026-0667 as a critical CWE-754 improper-check flaw affecting SCADAPack 47x/47xi and RemoteConnect when communicating over Modbus TCP. The vendor says the issue could lead to arbitrary code execution, denial of service, and loss of confidentiality and integrity, and recommends upgrading to the fixed releases or applying OT segmentation, RTU firewall restrictions, and disabling the logic debug service.
- Vendor
- Schneider Electric
- Product
- SCADAPack™
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-10
- Original CVE updated
- 2026-03-17
- Advisory published
- 2026-02-10
- Advisory updated
- 2026-03-17
Who should care
OT/ICS operators, plant engineers, and security teams running Schneider Electric SCADAPack 47x/47xi or RemoteConnect, especially where Modbus TCP is reachable from less-trusted networks.
Technical summary
The advisory identifies a CWE-754 improper check for unusual or exceptional conditions in Modbus TCP handling. According to the source, this can affect confidentiality, integrity, availability, and may permit arbitrary code execution or denial of service. Vendor-fixed releases are SCADAPack 47x/47xi firmware 9.12.2 on SCADAPack 47x/47xi version R3.4.2, and RemoteConnect R3.4.2.
Defensive priority
Critical. Prioritize patching or controlled upgrade planning immediately, then reduce exposure with network segmentation and service hardening if remediation will be delayed.
Recommended defensive actions
- Upgrade SCADAPack 47x/47xi to firmware 9.12.2 on R3.4.2.
- Upgrade RemoteConnect to R3.4.2.
- If you cannot remediate immediately, follow the SCADAPack Cybersecurity Guide section 8.3 on secured communication.
- Segment OT networks and use the RTU firewall service to block unauthorized access to services.
- Disable the logic debug service where it is not required.
- Verify asset inventory for affected SCADAPack and RemoteConnect deployments and prioritize reachable Modbus TCP paths.
Evidence notes
CISA's CSAF advisory ICSA-26-076-02, republished from Schneider Electric's SEVD-2026-041-01 notice, lists affected SCADAPack 47x and 47xi firmware / R3.4.2 combinations and RemoteConnect, describes the flaw as CWE-754 over Modbus TCP, and provides vendor fixes plus mitigations. The advisory revision history shows the initial release on 2026-02-10 and CISA republication on 2026-03-17.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-0667 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-0667
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-0667 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0667
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/ww/en/download/document/7EN52-0390
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.