www.securityweek.com 8/12/2026, 8:02:19 AM · external

Siemens, Schneider, Phoenix Patch Critical ICS Flaws in August

Siemens, Schneider, Phoenix Patch Critical ICS Flaws in August
CyberSIXT Evidence Panel

IN August 2026, major industrial companies Siemens, Schneider Electric, and Phoenix Contact released Patch Tuesday advisories addressing critical vulnerabilities in their Industrial Control System (ICS) products. Siemens published 10 advisories, including one for a high-severity missing-authentication flaw in the Simatic IoT2050, potentially allowing unauthenticated remote code execution.

Critical flaws were also fixed in Siveillance Video Management Servers and several applications, while medium-severity issues were addressed in Ruggedcom devices and Desigo controllers. Schneider Electric reported two vulnerabilities in its NetBotz and PowerChute products, relating to command execution and excessive authentication attempts. Phoenix Contact revealed vulnerabilities in PLCnext firmware that could lead to denial-of-service (DoS) or unexpected behavior.

The cybersecurity agency CISA also published advisories for vulnerabilities in various products. This patch cycle highlights the ongoing need for robust cybersecurity in industrial environments.

View Primary Source Via www.securityweek.com

Article by CyberSIXT