← All Advisories

CVE-2026-9716

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-9716

Key Details

CVECVE-2026-9716
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-07-01
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsSchneider Electric powerlogic_p7_firmware and Schneider Electric PowerLogic™ P7
Classified asCWE-476 (NULL Pointer Dereference)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Schneider Electricpowerlogic_p7_firmware
Schneider ElectricPowerLogic™ P7
SubsystemsGeneral OT
SectorsMultiple

What to Know

CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces.

What to Do

Monitor Schneider Electric's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-9716
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-9716
Vendor advisoryhttps://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-03.pdf