Schneider Tells SCADAPack Users to Stop Using Secure Lock
Every version of the SCADAPack x70 family is listed in ICSA-26-258-04, with no firmware fix. The remedy is a configuration change: drop the legacy Secure Lock feature and use role-based access control.

CISA republished Schneider Electric's SCADAPack advisory on 15 September as ICSA-26-258-04. The original, SEVD-2026-251-03, came out on 8 September. It concerns CVE-2026-81861, a CWE-522 insufficiently protected credentials weakness, scored 6.5 medium with vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.
The affected list is short to write and long to act on: SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx and 32, all versions. CISA's description of the impact is that it could enable unauthorised access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality. The researcher credited is Abhinav Agarwal.
There is no firmware fix. Schneider's remediation is to stop using the legacy Secure Lock feature and use role-based access control instead, and to enable the RTU firewall service to restrict unauthorised access. Further detail sits in the SCADAPack Cybersecurity Guide.
The medium CVSS score understates the work involved. SCADAPack RTUs live at unmanned pipeline stations, wellheads and remote water sites, where the configuration is not a settings file but the process logic itself. A remedy that is a configuration change rather than a patch means touching every unit in the fleet — and on sites some operators visit once a year, that is a scheduling problem more than a security one.
It also puts operators in the awkward position of retiring a feature that was documented and recommended at the time it was deployed. The sectors listed are critical manufacturing and energy, worldwide.