Skip to content
Sungrow Patches Critical iSolarCloud Vulnerability Exposing Solar Plants

Sungrow Patches Critical iSolarCloud Vulnerability Exposing Solar Plants

First seen 8 Oct 2026, 16:41 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 17:35 UTC
  • •Sungrow patched a critical vulnerability allowing unauthorized access to its iSolarCloud platform.
  • •The flaw affected solar plants globally, with no evidence of exploitation beyond the reporting researcher.
  • •Sungrow is conducting further security assessments to enhance its cybersecurity measures.

Sungrow has patched a critical vulnerability in its iSolarCloud platform that allowed unauthorized access to accounts without authentication. The flaw, reported by Jakkaru on August 22, affected the cloud service managing solar plants, inverters, and battery storage systems globally. Sungrow deployed an emergency patch on August 25, and follow-up tests confirmed the vulnerability was no longer exploitable. The vulnerability posed a risk to customers and energy operators in regions including Europe, China, and Australia. Sungrow's investigation revealed no evidence of exploitation beyond the reporting researcher, and it has committed to further security assessments. Jakkaru noted that similar vulnerabilities could exist in other inverter manufacturers' systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-22
Vulnerability reported to Sungrow
An independent researcher working with Jakkaru reported the vulnerability affecting iSolarCloud.
Pv-Magazine
2026-08-25
Emergency patch deployed
Sungrow deployed an emergency patch across all iSolarCloud levels to address the vulnerability.
Pv-Magazine
2026-09-15
Follow-up test confirms patch effectiveness
Jakkaru conducted a follow-up test and confirmed that the vulnerability could no longer be reproduced.
Pv-Magazine

More articles in this cluster (2)

Following this threat?

Track APsystems in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What regions are affected by this vulnerability?
The vulnerability affects customers and energy operators in Europe, China, Australia, and other regions.
Was there any exploitation of this vulnerability?
Sungrow found no evidence of exploitation beyond the reporting researcher, and no customer data leaks were reported.
What steps is Sungrow taking post-disclosure?
Sungrow is conducting further independent security assessments and implementing improvements based on the findings.