Schneider Electric has disclosed a vulnerability in its Easergy MiCOM Px40 Series products, according to a CISA Industrial Control Systems advisory (ICSA-26-190-03) published July 9, 2026. The Easergy MiCOM Px40 is a protection and automation relay system deployed in medium-voltage distribution and grid automation infrastructure.
The advisory confirms Schneider Electric's awareness of the issue but the provided source material does not contain specific details about the vulnerability's nature, attack vector, affected firmware versions, or remediation timeline. CISA's official advisory page and the detailed CSAF (Common Security Advisory Framework) JSON file contain the technical specifics, but these details are not fully captured in the initial alert.
Why this matters: Grid protection relays are critical infrastructure components. They monitor electrical systems, detect faults, and trigger protective actions—often automatically and in milliseconds. A vulnerability in this class of equipment could potentially allow unauthorized monitoring, manipulation of protective logic, or interference with automated responses to grid disturbances. The impact depends entirely on the vulnerability's technical characteristics and whether it requires local access or can be exploited remotely.
The Px40 series serves utilities and industrial sites managing medium-voltage networks, meaning affected installations could span regional transmission and distribution operators, large industrial facilities, and critical infrastructure operators. The geographic and operational scope of deployed units is not yet public.
What to watch next: Monitor CISA and Schneider Electric channels for:
- Confirmation of which firmware versions are affected
- Whether a fix is available or only workarounds exist
- Guidance on network segmentation or access controls as interim protection
- Any indicators that the vulnerability is being actively exploited in the wild
For infrastructure operators with Px40 relays in service, immediate action should focus on asset inventory and liaison with your Schneider Electric support channel to understand your specific exposure and available mitigations. Do not wait for a patch announcement—establish a communication plan with your vendor now.

