Schneider Electric, Siemens, and Aveva have issued their September 2026 Patch Tuesday advisories, detailing security vulnerabilities found in their Industrial Control Systems (ICS) products. These advisories inform customers about necessary updates to mitigate potential risks.
Schneider Electric published four new security advisories and updated four others. A critical authentication vulnerability, CVE-2026-3869 with a CVSS score of 9.2, was resolved in Modicon M580 and Modicon M580 Safety controllers. High-severity bugs in PowerLogic T300 and EcoStruxure IT Data Center Expert, along with a medium-severity defect in SCADAPack x70 products, were also patched. Updates for older security weaknesses were rolled out for the Modicon MC80 controller.
Siemens released nine new advisories and updated nine others since the last Patch Tuesday. Critical-severity vulnerabilities were addressed in Reyrolle 7SR5, Open Interface Services (OIS), Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT. High-severity issues were fixed in Desigo CC, Teamcenter, Mendix SAML module, and Element Maps. Siemens also deployed updates to resolve the Copy Fail Linux kernel vulnerability (CVE-2026-31431), which could allow root shell access.
Aveva published an advisory covering four flaws in the PIMBoards component of Pipeline Integrity Monitor, including high-severity bugs related to hardcoded encryption keys and MD5 password hashing. A medium-severity unsafe deserialization vulnerability in Enterprise SCADA, potentially leading to remote code execution, was also warned about. Rockwell Automation previously released nine security advisories for critical and high-severity flaws in products like RSLinx Classic, 1756-ENBT module, and FactoryTalk Historian Machine Edition.
These patches are crucial for protecting industrial control systems from cyber threats. Vulnerabilities in ICS products can lead to operational disruptions, data breaches, and safety hazards in critical infrastructure. Regular patching helps maintain the integrity and availability of these systems.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Schneider Electric, Siemens, and Aveva released September 2026 Patch Tuesday advisories addressing multiple vulnerabilities, including critical flaws, in their Industrial Control Systems (ICS) products. These patches are important for maintaining the security and operational integrity of critical infrastructure and industrial environments.