CVE-2026-6866General(schneider-electric / ecostruxure_panel_server_pas400)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for schneider-electric ecostruxure_panel_server_pas400 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1188

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ecostruxure_panel_server_pas400
  • ecostruxure_panel_server_pas400_firmware
  • ecostruxure_panel_server_pas600
  • ecostruxure_panel_server_pas600_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-21); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
ecostruxure_panel_server_pas400ecostruxure_panel_server_pas400_firmwareecostruxure_panel_server_pas600ecostruxure_panel_server_pas600_firmwareecostruxure_panel_server_pas600v2ecostruxure_panel_server_pas600v2_firmwareecostruxure_panel_server_pas800ecostruxure_panel_server_pas800_firmwareecostruxure_panel_server_pas800v2ecostruxure_panel_server_pas800v2_firmware

1 version affected across 10 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-21: 1Mentions · 2026-06-11: 1Active Exploitation · 2026-06-11: 1Technical Details · 2026-06-11: 105-2106-11
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-211
General1
2026-06-111
Active Exploitation1
Full discourse2 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Schneider ❗ CVE-2026-6866 ❗ CVE-2026-4827 ❗ CVE-2025-0327 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-schneider-2/ https://t.co/tGEmrn1kEY

    Post summary

    The post lists three Schneider product CVEs and offers external links for additional information, but provides no specific technical, exploit, or mitigation details.

    00011813
    6.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals attackers exploiting CVE-2026-6866 can gain admin control when Schneider Electric EcoStruxure Panel Server credentials revert to defaults. Researchers observed lateral movement across connected OT systems following initial compromise. Runtime segmentation helps contain post-compromise activity in critical infrastructure networks. #OTSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/schneider-electric-ecostruxure-panel-server-credential-reset-flaw-cve-2026-6866

    Post summary

    Researchers report active exploitation of CVE‑2026‑6866, allowing attackers to gain admin control via default credentials and subsequently perform lateral movement across connected OT systems.

    0000045
    1.9K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
HWschneider-electricecostruxure_panel_server_pas400---
OSschneider-electricecostruxure_panel_server_pas400_firmware---
HWschneider-electricecostruxure_panel_server_pas600---
OSschneider-electricecostruxure_panel_server_pas600_firmware---
HWschneider-electricecostruxure_panel_server_pas600v2---
OSschneider-electricecostruxure_panel_server_pas600v2_firmware---
HWschneider-electricecostruxure_panel_server_pas800---
OSschneider-electricecostruxure_panel_server_pas800_firmware---
HWschneider-electricecostruxure_panel_server_pas800v2---
OSschneider-electricecostruxure_panel_server_pas800v2_firmware---

Explore more