www.securityweek.com 9 Sept 2026, 10:49 UTC

ICS Patch Tuesday Fixes Critical Schneider, Siemens Flaws

ICS Patch Tuesday Fixes Critical Schneider, Siemens Flaws
CyberSIXT Evidence Panel Source marked as original reporting

SCHNEIDER Electric’s September 2026 Patch Tuesday advisory batch centres on its ICS portfolio, with four new advisories and updates to four others. The most critical flaw is an authentication vulnerability in the Modicon M580 and Modicon M580 Safety controllers, tracked as CVE-2026-3869, rated at CVSS 9.2.

In addition, Schneider Electric addressed high-severity issues in the PowerLogic T300 platform (formerly Easergy T300 RTU) and EcoStruxure IT Data Center Expert, plus a medium-severity defect in SCADAPack x70 products. The company also updated older advisories to note patches for the Modicon MC80 controller. The net effect is a broad tightening of access controls and remote-execution possibilities across multiple ICS lines.

Siemens contributed nine advisories since the last Patch Tuesday, with seven released on 8 September. Four of these cover critical-severity vulnerabilities affecting Reyrolle 7SR5, Open Interface Services (OIS), Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT. Other newly disclosed flaws are high-severity in Desigo CC, Teamcenter, Mendix SAML module, and Element Maps.

Siemens also flagged updates to mitigate the Copy Fail Linux kernel vulnerability (CVE-2026-31431, CVSS 7.8) that could permit a root shell. Aveva’s advisory focuses on four flaws in the PIMBoards component of Pipeline Integrity Monitor; two are high severity, including a hardcoded encryption key that could expose sensitive data and MD5-hashed passwords that might enable password reversal. Aveva also warned of a medium-severity unsafe deserialization vulnerability in Enterprise SCADA that could enable remote code execution.

Rockwell Automation published nine advisories covering critical- and high-severity flaws across RSLinx Classic, the 1756-ENBT module, FactoryTalk Historian ME, Activation Manager, Redundancy Module Configuration Tool, ControlFLASH, ArmorStart motors, and several GuardLogix/CompactLogix controllers.

The broader ongoing Patch Tuesday activity is complemented by CISA advisories parallel to the updates from the three OEMs, underscoring the evolving ICS risk landscape as vendors push mitigation across a wide product set.

View full article

Article by CyberSIXT