Ask our Experts
Didn't find what you are looking for? Ask our experts!
New Community Ranking System
Our Community ranking system has recently been updated. You may notice changes in user rankings and receive system messages or notifications. If you have questions about how the new ranking works, please refer to the announcement post for more details (click here).
Schneider, APC support forum to share knowledge about installation and configuration for Data Center and Business Power UPSs, Accessories, Software, Services.
Search in
Please select a country to continue with beta search.
Free
EnglishStrengthen your foundational knowledge in Data Centers for free, enroll in this path today and start your learning journey!
Link copied. Please paste this link to share this article on your social media post.
Posted: 2026-05-16 09:33 AM
The version of log4j-core-2.25.3.jar used in Powerchute Serial Shutdown 1.5 has the two vulnerabilities listed in the title, CVE-2026-34478 & CVE-2026-34480.
The are both HIGH vulnerabilities (CVSS 7.5) but despite being published a month ago, there is no update for Powerchute Serial Shutdown or even an acknowledgement of the issue on Schneider's security page - https://www.se.com/ww/en/work/support/cybersecurity/security-notifications/
When can we expect this to be addressed? Like most businesses running in the 21st century, we have to patch vulnerabilities within two weeks but this just isn't currently possible.
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2026-06-03 04:51 AM
Does anybody from Schneider contribute to this community?
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2026-06-08 04:11 AM
Mitigation scripts for CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480 are available attached to Schneider Electric FAQ000281802
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2026-06-08 05:50 AM
Thanks for the update and pointer to a patch.
I don't wish to seem ungrateful but Schneider really need to do better with regards to responding to security issues in their products. Enterprises are expected to patch security issues within a couple of weeks - waiting two months for a software fix is just not satisfactory and becomes a criteria for future purchases.
Link copied. Please paste this link to share this article on your social media post.
You’ve reached the end of your document
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.