CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Schneider Electric IGSS

criticalCVE-2026-12927
View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The IGSS product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could result in the loss of control of the system. The following versions of Schneider Electric IGSS are affected: IGSS () IGSS Definition (Def.exe) module vers:intdot/<=18.0.0.26124, 18.0.0.26125 () CVSS Vendor Equipment Vulnerabilities v3 7.8 Schneider Electric Schneider Electric IGSS Out-of-bounds Write Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All + CVE-2026-12927 An out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition. View CVE Details Affected Products Schneider Electric IGSS Vendor: Schneider Electric Product Version: Product Status: fixed, known_affected Remediations Vendor fix Version 18.0.0.26125 of the IGSS Definition module includes a fix for this vulnerability and is available for download through IGSS Master > Update IGSS Software or here: https://igss.schneider-electric.com/igss/igssupdates/v180/IGSSUPDATE.ZIP https://igss.schneider-electric.com/igss/igssupdates/v180/IGSSUPDATE.ZIP Mitigation If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Avoid executing commands, importing or opening files from untru

CSIRTS triage

What
Failure to apply remediation may risk loss of data or arbitrary code execution.
Who is affected
Deployments of the IGSS Definition module in the specified version range.
Urgency
Remediation is urgent due to the critical severity and potential for loss of control.
Action
Apply the provided remediation for the IGSS Definition module.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch IGSS

Get an email when a new IGSS advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-07-30
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-12927coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories