Security1 distinct publisher2 min readPublished
The session-hijack bug now lists 13 MiCOM P-series relays alongside the EPAS gateway and the substation HMI, which turns remediation into a fleet inventory exercise rather than a single firmware push. CISA's text names no attack vector.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Session hijacking reads differently depending on what the session controls. Schneider's own product descriptions inside the advisory set the stakes: EPAS-GTW exists to remotely monitor and operate electrical processes [4], EPAS-UI is an HMI SCADA for electrical networks and substation operations [5], the MiCOM C264 is a modular substation or bay controller and smart RTU [7], and the MiCOM P30 and P40 families are protection and control relays for medium, high and extra high voltage networks [6]. CISA states the consequence as malicious actors performing unauthorized operations within the affected system [2]. On this equipment, an operation is a switching action or a protection setting.
The version table is where the actual work sits. In the text supplied, 34 version lines are listed before the list is cut off mid-entry [20][16]. Twenty-seven carry the CVE-2026-4827 tag and seven do not [20]. Of those seven, three are strings identical to the upper bound of a tagged range: P139.678.700, P439.678.700 and P539.678.700 all appear once inside a "less than or equal to" affected range and once on their own [21]. Two more sit one increment above a tagged ceiling, with C264 D7.34 listed against affected builds up to D7.33, and Easergy C5 1.1.18 against affected builds up to 1.1.17 [21][8][13]. That pattern is consistent with fixed builds being carried in the same table, but nothing in the excerpt labels them that way [15]. Saitel DP up to 11.06.36 and EasyLogic T150 up to 11.06.30 also appear with no CVE against them [12].
The numbering schemes do not line up across the estate. D7.33 for the C264 [8], 02.502.103 for the PowerLogic P5, 2.9.4 for the T300, 11.08.02 for the T500 [11], 6.4.616.200.100 for the gateway and 3.0.3 for the user interface [9] are six different conventions, so matching an installed base against this advisory means recording model plus exact firmware string per device before any patch decision is possible.
On exploitability, the material is thin and should be read that way. The supplied advisory carries no CVSS score, no attack vector and no statement about known exploitation [17]. That leaves reachability as the variable operators actually hold: which hosts can open a session to an EPAS gateway or an EPAS-UI console, and from which network. The relays and bay controllers behind those sessions are the reason the question is worth answering [6][7].
What Update A adds is scope [1], and scope decides the unit of work: the substation estate rather than any one product line.
Ranked by verification strength, evidence, and original report placement.
The affected version list in the supplied advisory text is cut off mid-entry, ending with the fragment "- Eas".
CISA published an ICS advisory titled "Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)", identified in the source path as ICSA-26-169-07.
The advisory states Schneider Electric is aware of a vulnerability in the listed products and that failure to apply the fix provided may risk session hijacking, which could result in malicious actors performing unauthorized operations within the affected system.
The CVE identifier tagged against the affected version entries is CVE-2026-4827.
The advisory describes the EcoStruxure Power Automation System Gateway (EPAS-GTW) as a scalable, interoperable and rugged communication gateway that helps to remotely monitor and operate electrical processes.
The advisory describes the EcoStruxure Power Automation System User Interface (EPAS-UI) as an HMI SCADA designed for electrical networks and substation operations.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
security
Rockwell folds four RSLinx Classic CIP crash flaws into a single 4.60 upgrade1 distinct publisher
security
CISA revises the Mitsubishi FA advisory a fourth time for one UDP denial-of-service bug1 distinct publisher
product
The UK plant that went dark for four days was too small to have to tell anyone1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary issuer, single channel, truncated copy
For an ICS bulletin, CISA is the record, and the things that matter most here — the CVE tag, the per-product version ceilings, the session-hijack consequence — are exactly what such a document is authoritative about. Two things keep this from scoring higher. Nobody has independently touched it: not Schneider's own security bulletin, not a single trade outlet, so the fixed-version question stays an inference. And the copy we hold stops mid-sentence at "Eas" in the restated affected-products section, meaning we are grading a document we can see is incomplete.
Footprint asserted, remediation unmeasured
The only uptake fact in the story runs the wrong way: CISA tells us these relays, RTUs and gateways are deployed worldwide across four critical-infrastructure sectors, which sizes the problem, not the response. Nothing says how many devices sit below a tagged ceiling, how quickly anyone is stepping to the higher builds, or whether a single session has been hijacked. The one dated event on the record is CISA revising its own advisory.
Our opacity charge outruns the text
The fleet-inventory reading holds up — fifteen MiCOM models plus a family-wide P40 wildcard genuinely is an inventory exercise, not a firmware push. The overreach is in our line that CISA names no attack vector: the advisory classifies the flaw as CWE-331 insufficient entropy exploitable by an attacker on the network, which is a vector as far as it goes. We also left the untagged version lines looking more mysterious than they are, when T300 2.9.5 sitting above a ≤2.9.4 ceiling and iPMFLS 64.2025.0.14 above ≤64.2025.0.13 read plainly enough. Modestly overstated, in the direction of confusion rather than danger.
Disinterested channel, vendor prose inside it
CISA has no stake in how this lands, and that is most of why the document reads straight. But the descriptions are Schneider's: "scalable, interoperable, and rugged" survived the trip from a datasheet into a security advisory, and the vendor's preferences show in the shape of the disclosure — apply the fix, no severity figure, no exposure estimate, remediation framed as the operator's task. That is the ordinary gravity of vendor-supplied copy, not spin.
Solid on the table, thin on the meaning
We can stand behind what the advisory prints: the identifier, the ceilings, the model count, the CWE class. We are much less sure about what it means — which builds actually remediate, how severe this is, whether anything downstream of the truncation changes the scope. The tally error in our own reading of the version list is the honest caution here: when a story rests on counting rows in one table, small mistakes are cheap to make and there is no second publisher to catch them.