Patch Tuesday: Siemens, Schneider, Phoenix Contact Fix ICS Flaws

Siemens, Schneider Electric and Phoenix Contact released August Patch Tuesday advisories fixing multiple ICS vulnerabilities, including an unauthenticated remote-code-execution flaw in Siemens Simatic IoT2050 Advanced.

On Patch Tuesday in August 2026, Siemens, Schneider Electric and Phoenix Contact published security advisories addressing multiple vulnerabilities in industrial control system products.

Siemens posted 10 new advisories. The most severe corrects a missing-authentication vulnerability in Simatic IoT2050 Advanced devices that could allow a remote, unauthenticated attacker to execute arbitrary code on the underlying server with elevated privileges. Siemens also fixed a critical code-execution flaw in Siveillance Video Management Servers. High-severity issues affecting Solid Edge, Simcenter Nastran, Siemens License Server, Simcenter Femap, Parasolid and Logo! Soft Comfort were patched; those flaws could be used to crash applications, run arbitrary code, escalate privileges, read files or expose sensitive information. Siemens also addressed medium-severity issues in Ruggedcom devices and Desigo controllers.

Schneider Electric published two advisories for NetBotz 5 and PowerChute Serial Shutdown. The NetBotz updates resolve two vulnerabilities that could allow code or command execution. The PowerChute advisory patches an authentication-related weakness that could permit excessive authentication attempts, potentially leading to service disruption or access to system data.

Phoenix Contact issued a single advisory covering multiple vulnerabilities in PLCnext firmware. According to the advisory, unauthenticated attackers could exploit the flaws to cause denial-of-service conditions, trigger unexpected device behavior or inject malicious SQL queries.

The U.S. Cybersecurity and Infrastructure Security Agency released three new advisories on Tuesday covering vulnerabilities in Pulsetto, Mira (Quanovate Tech) and select Johnson Controls products. Other vendors, including Honeywell, published fixes for building management system products earlier in August.

Vendors provided patches and recommended mitigations. System operators and administrators are advised to review vendor notices, apply supplied updates, prioritize devices exposed to untrusted networks and follow any configuration or access-control guidance included with the fixes. The advisories cover PLC firmware, remote-management appliances, video management systems and engineering tools used in industrial environments.

Articles by this author