ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
Several major industrial automation vendors – Schneider Electric, Siemens, and Aveva – released Patch Tuesday advisories addressing critical and high-severity vulnerabilities in their Industrial Control Systems (ICS) products. These updates focus on authentication flaws, data decryption issues, and remote code execution vulnerabilities, highlighting the ongoing need for proactive security measures in critical infrastructure.
Industrial automation giants Schneider Electric, Siemens, and Aveva have released Patch Tuesday advisories addressing a range of security vulnerabilities within their Industrial Control Systems (ICS) products. Schneider Electric published four new advisories and updated four existing ones, including a 2019-released vulnerability. The most critical issue involves a critical authentication flaw in Modicon M580 and Modicon M580 Safety controllers, tracked as CVE-2026-3869 and carrying a CVSS score of 9.2.
Siemens released nine new advisories since the last Patch Tuesday, including seven on September 8, and updated nine other advisories. Several of these address critical-severity vulnerabilities in Reyrolle 7SR5, Open Interface Services (OIS), Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT. Additionally, Siemens announced updates to resolve a Copy Fail Linux kernel vulnerability disclosed in April (CVE-2026-31431, CVSS score of 7.8), which could allow attackers to gain root shell access.
Aveva published an advisory covering four flaws in the PIMBoards component of Pipeline Integrity Monitor, including a hardcoded encryption key that allows decryption of sensitive information and a high-severity vulnerability related to MD5-hashed passwords. Aveva also warned of a medium-severity unsafe deserialization vulnerability in Enterprise SCADA that could lead to remote code execution.
Rockwell Automation also published nine security advisories covering critical and high-severity flaws in RSLinx Classic and high-severity bugs in the 1756-ENBT module, FactoryTalk Historian Machine Edition (ME), FactoryTalk Activation Manager, Redundancy Module Configuration Tool, ControlFLASH, ArmorStart Distributed Motor Controllers, and the CompactLogix 5380/5480/5580, GuardLogix 5580, and Compact GuardLogix 5380 controllers. CISA has also published advisories for vulnerabilities in various products including CareCam, Tycon Systems, Pyramid Solutions, Inductive Automation, IXON, OPCFoundation, Ebyte, All-Line Equipment Company, Applied Systems Engineering, Xiiaozet, Furuno, Bendix, PayRange, Rently, Johnson Controls, Flow Neuroscience, Andritz, Hitachi Energy, Haiwell, Pulsetto Vagus, and Mira Hormone products.