ICS/OT

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.

ICS security

Industrial giants Schneider Electric, Siemens, and Aveva have published September 2026 Patch Tuesday advisories, informing customers about vulnerabilities found in their ICS products.

Schneider Electric published four new security advisories and updated four others, including one originally released in 2019.

The most severe of the newly addressed issues is a critical authentication vulnerability in Modicon M580 and Modicon M580 Safety controllers. Tracked as CVE-2026-3869, the flaw has a CVSS score of 9.2.

Schneider Electric also resolved high-severity bugs in the PowerLogic T300 platform (formerly Easergy T300 RTU) and its EcoStruxure IT Data Center Expert product, and a medium-severity defect in SCADAPack x70 products.

Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference

On Tuesday, the company also updated four security advisories that cover older security weaknesses to add mentions of patches being rolled out for the Modicon MC80 controller.

Advertisement. Scroll to continue reading.

Siemens has published nine new advisories since the last Patch Tuesday, including seven on September 8. It also updated nine other advisories.

Four of the newly released advisories cover critical-severity vulnerabilities in Reyrolle 7SR5, Open Interface Services (OIS), Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT.

The remaining flaws are high-severity issues in Desigo CC, Teamcenter, Mendix SAML module, and Element Maps.

Additionally, the company announced the rollout of updates for several products to resolve the Copy Fail Linux kernel vulnerability disclosed in April. Tracked as CVE-2026-31431 (CVSS score of 7.8), it allows attackers to achieve root shell access.

Aveva on Tuesday published an advisory covering four flaws in the PIMBoards component of Pipeline Integrity Monitor. Two are high-severity bugs: a hardcoded encryption key allows attackers to decrypt sensitive information, and passwords being hashed with MD5 could allow attackers to reverse-engineer administrative passwords.

Since the previous Patch Tuesday, Aveva also warned of a medium-severity unsafe deserialization vulnerability in Enterprise SCADA that could potentially lead to remote code execution.

Last week, Rockwell Automation published nine security advisories that cover critical- and high-severity flaws in RSLinx Classic and high-severity bugs in the 1756-ENBT module, FactoryTalk Historian Machine Edition (ME), FactoryTalk Activation Manager, Redundancy Module Configuration Tool, ControlFLASH, ArmorStart Distributed Motor Controllers, and the CompactLogix 5380/5480/5580, GuardLogix 5580, and Compact GuardLogix 5380 controllers.

Since the previous Patch Tuesday, CISA has published advisories for vulnerabilities in CareCam, Tycon Systems, Pyramid Solutions, Inductive Automation, IXON, OPCFoundation, Ebyte, All-Line Equipment Company, Applied Systems Engineering, Xiiaozet, Furuno, Bendix, PayRange, Rently, Johnson Controls, Flow Neuroscience, Andritz, Hitachi Energy, Haiwell, Pulsetto Vagus, and Mira Hormone products.

Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact

Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell

Related Content

ICS/OT

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.

Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.

Artificial Intelligence

Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models.

Government

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

ICS/OT

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.

Vulnerabilities

Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities.

ICS/OT

Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville.

Vulnerabilities

Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version