PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-0667 Schneider Electric CVE debrief

Schneider Electric and CISA describe CVE-2026-0667 as a critical CWE-754 improper-check flaw affecting SCADAPack 47x/47xi and RemoteConnect when communicating over Modbus TCP. The vendor says the issue could lead to arbitrary code execution, denial of service, and loss of confidentiality and integrity, and recommends upgrading to the fixed releases or applying OT segmentation, RTU firewall restrictions, and disabling the logic debug service.

Vendor
Schneider Electric
Product
SCADAPack™
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-10
Original CVE updated
2026-03-17
Advisory published
2026-02-10
Advisory updated
2026-03-17

Who should care

OT/ICS operators, plant engineers, and security teams running Schneider Electric SCADAPack 47x/47xi or RemoteConnect, especially where Modbus TCP is reachable from less-trusted networks.

Technical summary

The advisory identifies a CWE-754 improper check for unusual or exceptional conditions in Modbus TCP handling. According to the source, this can affect confidentiality, integrity, availability, and may permit arbitrary code execution or denial of service. Vendor-fixed releases are SCADAPack 47x/47xi firmware 9.12.2 on SCADAPack 47x/47xi version R3.4.2, and RemoteConnect R3.4.2.

Defensive priority

Critical. Prioritize patching or controlled upgrade planning immediately, then reduce exposure with network segmentation and service hardening if remediation will be delayed.

Recommended defensive actions

  • Upgrade SCADAPack 47x/47xi to firmware 9.12.2 on R3.4.2.
  • Upgrade RemoteConnect to R3.4.2.
  • If you cannot remediate immediately, follow the SCADAPack Cybersecurity Guide section 8.3 on secured communication.
  • Segment OT networks and use the RTU firewall service to block unauthorized access to services.
  • Disable the logic debug service where it is not required.
  • Verify asset inventory for affected SCADAPack and RemoteConnect deployments and prioritize reachable Modbus TCP paths.

Evidence notes

CISA's CSAF advisory ICSA-26-076-02, republished from Schneider Electric's SEVD-2026-041-01 notice, lists affected SCADAPack 47x and 47xi firmware / R3.4.2 combinations and RemoteConnect, describes the flaw as CWE-754 over Modbus TCP, and provides vendor fixes plus mitigations. The advisory revision history shows the initial release on 2026-02-10 and CISA republication on 2026-03-17.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-0667 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-0667

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-0667 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0667

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.se.com/ww/en/download/document/7EN52-0390

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.