Schneider, Siemens Patch Critical ICS Flaws in September Update

Schneider Electric and Siemens issued Patch Tuesday advisories addressing critical industrial control system vulnerabilities, including a CVSS 9.2 authentication bug in Modicon M580 (CVE-2026-3869).

On Patch Tuesday in September 2026, Schneider Electric, Siemens and Aveva published security advisories for industrial control system products. The updates cover multiple critical and high-severity vulnerabilities in controllers, protection relays, management platforms and monitoring tools. Rockwell Automation issued related advisories the previous week and federal authorities released notices for several vendors since the last Patch Tuesday.

Schneider Electric posted four new security advisories and updated four existing ones, including an advisory originally issued in 2019. The most severe item is an authentication bypass in Modicon M580 and Modicon M580 Safety controllers tracked as CVE-2026-3869 with a CVSS score of 9.2. Schneider also fixed high-severity defects in the PowerLogic T300 platform (formerly Easergy T300 RTU) and EcoStruxure IT Data Center Expert, plus a medium-severity issue in SCADAPack x70 products. Notices on older advisories were updated to reflect patches being rolled out for the Modicon MC80 controller.

Siemens published nine new advisories and updated nine others. Four newly disclosed flaws were rated critical and affect Reyrolle 7SR5 protection relays, Open Interface Services (OIS), Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT. Additional high-severity issues were reported in Desigo CC, Teamcenter, the Mendix SAML module and Element Maps. Siemens announced rollouts for several products to remediate a Linux kernel vulnerability tracked as CVE-2026-31431 (CVSS 7.8) that can be exploited to gain a root shell.

Aveva released an advisory covering four vulnerabilities in the PIMBoards component of its Pipeline Integrity Monitor product. Two of those were classified as high severity: a hardcoded encryption key that could permit decryption of sensitive data and the use of MD5 for password hashing that could enable recovery of administrative credentials. Since the previous Patch Tuesday, Aveva also warned of a medium-severity unsafe deserialization flaw in Enterprise SCADA that under certain conditions may enable remote code execution.

Rockwell Automation published nine advisories last week addressing critical and high-severity issues, including flaws in RSLinx Classic and multiple controller and tool components such as the 1756-ENBT module, FactoryTalk Historian Machine Edition, FactoryTalk Activation Manager, Redundancy Module Configuration Tool, ControlFLASH, ArmorStart Distributed Motor Controllers, and CompactLogix and GuardLogix controllers. The U.S. Cybersecurity and Infrastructure Security Agency published advisories for vulnerabilities affecting a range of vendors, including Johnson Controls, Hitachi Energy, Inductive Automation, OPC Foundation and several other product suppliers.

Vendors report that patches and updates are available or are being distributed and advise customers to follow vendor guidance for mitigation and remediation. The posted CVSS scores describe potential impacts on confidentiality, integrity and availability; advisories note that exploited vulnerabilities could enable privilege escalation, remote code execution or loss of data confidentiality.

Industrial control systems operate power distribution, manufacturing and process industry equipment. Vulnerabilities in controllers, management platforms and monitoring tools can affect operational continuity and safety, and the September advisories include patched fixes and rollouts for multiple affected products.

Articles by this author