Schneider Electric patches IGSS Definition out-of-bounds write
CVE-2026-12927 hits the design-time module, not the running SCADA server, the exploit requires importing a malicious CGF file, so air-gapped integrator workstations with file-origin controls face the lowest practical risk.
TL;DR
CISA published advisory ICSA-26-211-04 for CVE-2026-12927, a CVSS 7.8 out-of-bounds write in Schneider Electric's IGSS Definition module (Def.exe). The vulnerability triggers when a malicious CGF configuration file is imported into the design-time tool, not the runtime SCADA server. Schneider Electric released patched version 18.0.0.26125. System integrators and MSPs who build IGSS mimic diagrams should patch immediately; the attack vector is local and requires user interaction, so air-gapped engineering workstations with enforced file-origin controls face materially lower exposure.
This is the fifth CISA advisory for Schneider Electric's IGSS platform since 2021, and the pattern is worth noting: the runtime components (Data Server, Dashboard, Update Service) have repeatedly drawn CVSS scores in the 8.8, 9.8 range with network-accessible attack vectors. This one is different.
CVE-2026-12927 lives in the IGSS Definition module, the design-time tool system integrators use to build mimic diagrams and configure plant representations before deploying them to production. The vulnerability is an out-of-bounds write (CWE-787) that fires when a malicious CGF (Configuration Group File) is imported. CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. That's local, no privileges, user interaction required. The exploit chain requires someone to hand the victim a poisoned CGF and convince them to import it.
Practically, that's a far narrower window than the 2022 IGSS Data Server CVE-2022-24310, which was network-exploitable at 9.8 with no user interaction. The Definition module isn't a listening service; it's a workstation application. If your integrators work from air-gapped engineering machines and enforce a rule that CGF files come only from known project directories, the exposure is low. If they're pulling configuration files from shared network locations or thumb drives, patch now.
Patched version 18.0.0.26125 is available through IGSS Master > Update IGSS Software or via Schneider Electric's update ZIP. Versions 18.0.0.26124 and prior are affected.
Researcher Michael Heinzl gets the acknowledgment on this one, no Zero Day Initiative involvement this round, which is itself a small data point on whether IGSS is attracting sustained external research attention or getting one-off finds.
Published ·Deep Fathom