PatchSiren cyber security CVE debrief
CVE-2026-27773 SWITCH EV CVE debrief
CVE-2026-27773 is a medium-severity exposure affecting SWTCH EV charging infrastructure, where authentication identifiers are publicly accessible via web-based mapping platforms. The main risk is reconnaissance: exposed identifiers can help an attacker identify and target charging assets, even if the advisory does not describe direct code execution or confirmed compromise. CISA published the advisory on 2026-02-26 and updated it on 2026-05-14 to adjust vendor spelling and add mitigations provided by SWTCH.
- Vendor
- SWITCH EV
- Product
- SWTCH EV swtchenergy.com vers:all/*
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-26
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-02-26
- Advisory updated
- 2026-05-14
Who should care
Operators and owners of SWTCH EV charging stations, EV charging infrastructure administrators, site reliability teams, and security teams responsible for OT/edge-connected equipment should review this advisory. Organizations that rely on mapping or discovery services for charger visibility should also verify what authentication-related identifiers are exposed publicly.
Technical summary
The advisory states that charging station authentication identifiers are publicly accessible through web-based mapping platforms. That exposure suggests an information-disclosure weakness rather than a direct device takeover path. CISA’s revision history says Update A added mitigations from SWTCH, including configuration changes for initial connections from untrusted chargers, additional scrutiny for onboarding and new connections, compensating monitoring and IP-based restrictions, and notes that some existing chargers may remain limited by legacy firmware or SSL/TLS compatibility constraints.
Defensive priority
Moderate. The issue is externally observable and can assist targeting, but the advisory does not indicate active exploitation or KEV listing. Prioritize exposure review and mitigation for internet-reachable or publicly indexed charger data, especially where legacy devices or compatibility constraints may limit immediate enforcement.
Recommended defensive actions
- Review whether charger authentication identifiers or related metadata are exposed through public mapping or discovery platforms.
- Apply SWTCH-provided mitigations and configuration changes intended to enforce stronger checks for initial connections from untrusted chargers.
- Validate that newly onboarded and newly connected devices are subject to the updated authentication, connection-control, and ingress-protection requirements.
- For deployed chargers with legacy firmware or SSL/TLS compatibility limitations, assess upgrade feasibility or retirement timelines.
- Use compensating controls such as monitoring and IP-based access restrictions to reduce exposure during remediation.
- Refer to the SWTCH Security portal for vendor guidance and remediation details.
- Coordinate with SWTCH support if your environment cannot fully enforce the updated security policy because of device-specific constraints.
Evidence notes
Primary evidence comes from the CISA CSAF advisory ICSA-26-057-06 / CVE-2026-27773, which explicitly says charging station authentication identifiers are publicly accessible via web-based mapping platforms. The advisory’s Update A revision history states that mitigations were added by SWTCH and that the vendor name was adjusted for accuracy. The provided advisory references include the official CISA advisory page and general CISA ICS guidance resources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-27773 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-27773
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-27773 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-27773
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.