CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Schneider Electric IGSS

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3571

As cited

Copy frozen at (site build).

vulnerabilities

Schneider Electric IGSS

Schneider Electric disclosed a high-severity out-of-bounds write vulnerability (CVE-2026-12927) in the IGSS Definition module of its Interactive Graphical SCADA System (IGSS) product. The flaw could lead to data loss or arbitrary code execution when a malicious CGF file is imported, affecting IGSS versions up to 18.0.0.26124. A patched version 18.0.0.26125 is available, and users who cannot patch immediately should avoid importing files from untrusted sources.

Why it matters: Industrial control system operators and integrators using IGSS must patch promptly to prevent potential loss of control over critical manufacturing and energy systems, especially since the vulnerability requires only local user interaction to exploit.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Schneider Electric IGSS

Schneider Electric disclosed a high-severity out-of-bounds write vulnerability (CVE-2026-12927) in the IGSS Definition module of its Interactive Graphical SCADA System (IGSS) product. The flaw could lead to data loss or arbitrary code execution when a malicious CGF file is imported, affecting IGSS versions up to 18.0.0.26124. A patched version 18.0.0.26125 is available, and users who cannot patch immediately should avoid importing files from untrusted sources.

Why it matters: Industrial control system operators and integrators using IGSS must patch promptly to prevent potential loss of control over critical manufacturing and energy systems, especially since the vulnerability requires only local user interaction to exploit.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary