Implement Role-Based Access Control (RBAC) as recommended by Schneider Electric and follow the Security Guidelines for Administrators. Configure network segmentation to restrict access between trusted and untrusted networks. Enable and implement the RTU firewall service to restrict unauthorized access to device services. Consult the SCADAPack Cybersecurity Guide for hardening and secured communication best practices. Apply all standard practices referenced in the SCADAPack Cybersecurity Guide, including locating control system networks behind firewalls and isolating them from business networks.
Quick answers
What is CVE-2026-81861?
Implement Role-Based Access Control (RBAC) as recommended by Schneider Electric and follow the Security Guidelines for Administrators. Configure network segmentation to restrict access between trusted and untrusted networks. Enable and implement the RTU firewall service to restrict unauthorized access to device services. Consult the SCADAPack Cybersecurity Guide for hardening and secured communication best practices. Apply all standard practices referenced in the SCADAPack Cybersecurity Guide, including locating control system networks behind firewalls and isolating them from business networks.
How severe is CVE-2026-81861?
medium, CVSS 6.5
Is CVE-2026-81861 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-81861 be mitigated?
Implement Role-Based Access Control (RBAC) as recommended by Schneider Electric and follow the Security Guidelines for Administrators. Configure network segmentation to restrict access between trusted and untrusted networks. Enable and implement the RTU firewall service to restrict unauthorized access to device services. Consult the SCADAPack Cybersecurity Guide for hardening and secured communication best practices. Apply all standard practices referenced in the SCADAPack Cybersecurity Guide, including locating control system networks behind firewalls and isolating them from business networks.
Implement Role-Based Access Control (RBAC) as recommended by Schneider Electric and follow the Security Guidelines for Administrators. Configure network segmentation to restrict access between trusted and untrusted networks. Enable and implement the RTU firewall service to restrict unauthorized access to device services. Consult the SCADAPack Cybersecurity Guide for hardening and secured communication best practices. Apply all standard practices referenced in the SCADAPack Cybersecurity Guide, including locating control system networks behind firewalls and isolating them from business networks.
Schneider Electric has disclosed a vulnerability in its SCADAPack x70 series of Remote Terminal Units. The issue, tracked as CVE-2026-81861, involves insufficiently protected credentials that could expose authentication information and lead to unauthorized access to RTU configuration through the Secure Lock functionality. The vulnerability affects SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32 models. Schneider Electric rates the base severity as medium with a CVSS v3.1 score of 6.5. No active exploitation has been reported, but the vendor recommends immediate implementation of Role-Based Access Control (RBAC) and network segmentation as mitigations.