ICS Patch Tuesday: Schneider Electric, Siemens, and Others Address Critical Flaws
Schneider Electric, Siemens, Aveva, and Rockwell Automation have released patches for critical and high-severity vulnerabilities affecting their industrial control system products.

September's Industrial Control Systems (ICS) Patch Tuesday has seen major vendors like Schneider Electric and Siemens issuing significant updates to address a range of vulnerabilities. Schneider Electric, in particular, released four new security advisories and updated four existing ones, highlighting ongoing efforts to secure critical infrastructure.
The most critical flaw addressed by Schneider Electric is CVE-2026-3869, an authentication vulnerability in Modicon M580 and Modicon M580 Safety controllers, carrying a CVSS score of 9.2. The company also resolved high-severity bugs in its PowerLogic T300 platform and EcoStruxure IT Data Center Expert product, alongside a medium-severity defect in SCADAPack x70 products. These updates underscore the persistent need for vigilance in securing operational technology (OT) environments.
Siemens has been equally active, publishing nine new advisories and updating nine others. Four of these new advisories tackle critical-severity vulnerabilities found in Reyrolle 7SR5, Open Interface Services (OIS), Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT. Additionally, Siemens is rolling out updates to address the Copy Fail Linux kernel vulnerability (CVE-2026-31431), which could allow attackers to gain root shell access.
Aveva has also published advisories detailing four flaws within the PIMBoards component of its Pipeline Integrity Monitor. Two of these are high-severity, including an issue with a hardcoded encryption key that could expose sensitive information and a flaw where MD5-hashed passwords might be reverse-engineered. A medium-severity unsafe deserialization vulnerability in Enterprise SCADA also poses a risk of remote code execution.
Rockwell Automation is not far behind, having released nine security advisories that cover critical and high-severity flaws across several of its products. These include issues in RSLinx Classic, the 1756-ENBT module, FactoryTalk Historian Machine Edition (ME), and various controller platforms like CompactLogix and GuardLogix.
The regular cadence of these ICS Patch Tuesdays, coupled with advisories from CISA for a broad spectrum of vendors including CareCam, Tycon Systems, and Johnson Controls, indicates a challenging landscape for ICS security. The sheer volume and variety of vulnerabilities being disclosed emphasize the interconnectedness of IT and OT security and the need for robust patch management strategies.
These updates are crucial for organizations operating critical infrastructure, as exploited vulnerabilities in ICS can lead to significant operational disruptions, safety incidents, and potential physical damage. The ongoing discovery and patching of these flaws highlight the dynamic nature of cybersecurity threats in the OT space and the continuous effort required to maintain system integrity and resilience.