Back to Blog
CVE-2021-22681: Schneider Electric Code Vulnerability — Utility Account Compromise (June 2026)
vulnerabilities

CVE-2021-22681: Schneider Electric Code Vulnerability — Utility Account Compromise (June 2026)

breachwire TeamOct 6, 20262 min read

CVE-2021-22681 — Schneider Electric Code Vulnerability

CVE-2021-22681 is a high-severity flaw in Schneider Electric's EcoStruxure Control Expert and related software, allowing attackers to bypass authentication and gain unauthorized access. The vulnerability is actively exploited, as seen in the June 2026 incident targeting California Water Service, with no workaround available—prompt patching is critical.

Attack Vector

Attackers leveraged stolen credentials to access customer accounts on two third-party platforms linked to California Water Service. The exploitation of CVE-2021-22681 enabled bypassing authentication controls, facilitating unauthorized access. No direct compromise of internal IT or OT systems was reported, but the attack demonstrates the risk of credential theft combined with unpatched software.

Who Is at Risk

Organizations using Schneider Electric EcoStruxure Control Expert and related products are at risk, especially those integrating with third-party service providers. California Water Service, one of the largest US water utilities, confirmed limited customer account compromise. Other water and energy sector organizations may also be vulnerable if CVE-2021-22681 remains unpatched.

Patch & Mitigate

  • Patch: Upgrade to the latest Schneider Electric EcoStruxure Control Expert version addressing CVE-2021-22681. Apply vendor patches immediately.
  • Workaround: None available; patching is required.
  • Detect: Monitor for unusual authentication attempts, especially from foreign IPs or using compromised credentials. Review logs for unauthorized access to third-party service integrations.

MITRE ATT&CK

  • TA0006 — Credential Access: Attackers used stolen credentials to access accounts.
  • TA0040 — Impact: The attack led to financial losses and account compromise at targeted utilities.

Source: https://www.cybersecuritydive.com/news/cisa-fbi-iran-hackers-target-water-energy/826025/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: