Authentication Algorithm Flaw in Schneider Electric PLCs
CVE-2026-3869

9.2CRITICAL

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-3869?

An authentication algorithm flaw exists within Schneider Electric's PLCs that may lead to significant risks, including the potential loss of confidentiality, integrity, and availability. If an application project running at a lower application level operates on the PLC, the inadequate authentication system can be exploited, compromising sensitive data and operational capabilities. It is crucial for users and system administrators to assess their systems' configurations and apply appropriate security measures to mitigate these risks.

Affected Version(s)

Modicon M580 All versions with an application level below 4.00

Modicon M580 Safety All versions with an application level below 4.20

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.