Pv-Magazine Sungrow Patches Critical iSolarCloud Vulnerability Exposing Solar Plants
Article Content
- •Sungrow patched a critical vulnerability allowing unauthorized access to its iSolarCloud platform.
- •The flaw affected solar plants globally, with no evidence of exploitation beyond the reporting researcher.
- •Sungrow is conducting further security assessments to enhance its cybersecurity measures.
Sungrow has patched a critical vulnerability in its iSolarCloud platform that allowed unauthorized access to accounts without authentication. The flaw, reported by Jakkaru on August 22, affected the cloud service managing solar plants, inverters, and battery storage systems globally. Sungrow deployed an emergency patch on August 25, and follow-up tests confirmed the vulnerability was no longer exploitable. The vulnerability posed a risk to customers and energy operators in regions including Europe, China, and Australia. Sungrow's investigation revealed no evidence of exploitation beyond the reporting researcher, and it has committed to further security assessments. Jakkaru noted that similar vulnerabilities could exist in other inverter manufacturers' systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track APsystems in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What regions are affected by this vulnerability?
Was there any exploitation of this vulnerability?
What steps is Sungrow taking post-disclosure?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…