
TRC analysis shows attackers exploited CVE-2026-8045, an XXE vulnerability in Schneider Electric's EcoStruxure IT Data Center Expert, to access sensitive server files and escalate privileges. The compromise enabled lateral movement across the network infrastructure. Runtime segmentation could help contain such post-exploitation activity within data center environments. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/schneider-electric-ecostruxure-it-data-center-expert-cve-2026-8045
Post summary
Travis Research Center reports that attackers actively exploited CVE-2026-8045, an XXE flaw in Schneider Electric's EcoStruxure IT, to gain file access, elevate privileges, and move laterally, with a recommendation to use runtime segmentation to limit spread.
