Industrial giants Schneider Electric, Siemens and AVEVA have published their September 2026 Patch Tuesday advisories, informing customers about vulnerabilities affecting their ICS products.
Schneider Electric published four new security advisories and updated four others, including one originally released in 2019.
The most severe of the newly addressed issues is a critical authentication vulnerability in Modicon M580 and Modicon M580 Safety controllers. Tracked as CVE-2026-3869, the flaw has a CVSS score of 9.2.
Schneider Electric also resolved high-severity vulnerabilities in the PowerLogic T300 platform, formerly known as the Easergy T300 RTU, and its EcoStruxure IT Data Center Expert product, as well as a medium-severity flaw affecting SCADAPack x70 products.
The company also updated four advisories covering older vulnerabilities to note the availability of patches for the Modicon MC80 controller.
Siemens has published nine new advisories since the previous Patch Tuesday, including seven released on September 8, and updated nine others.
Four of the new advisories cover critical-severity vulnerabilities affecting Reyrolle 7SR5, Open Interface Services (OIS), Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT.
The remaining advisories address high-severity vulnerabilities in Desigo CC, Teamcenter, the Mendix SAML module, and Element Maps.
Siemens also announced updates for several products affected by the Copy Fail Linux kernel vulnerability disclosed in April. Tracked as CVE-2026-31431 and carrying a CVSS score of 7.8, the flaw can allow attackers to obtain root shell access.
AVEVA published an advisory on Tuesday covering four vulnerabilities in the PIMBoards component of Pipeline Integrity Monitor.
Two are high-severity flaws: one involves a hardcoded encryption key that could allow attackers to decrypt sensitive information, while the other involves the use of MD5 for password hashing, potentially enabling attackers to recover administrative passwords.
Since the previous Patch Tuesday, AVEVA has also warned customers about a medium-severity unsafe deserialization vulnerability in Enterprise SCADA that could potentially lead to remote code execution.
Last week, Rockwell Automation published nine advisories covering critical- and high-severity vulnerabilities in RSLinx Classic, as well as high-severity flaws affecting the 1756-ENBT module, FactoryTalk Historian Machine Edition (ME), FactoryTalk Activation Manager, Redundancy Module Configuration Tool, ControlFLASH, ArmorStart Distributed Motor Controllers, and CompactLogix 5380, 5480 and 5580, GuardLogix 5580, and Compact GuardLogix 5380 controllers.
Since the previous Patch Tuesday, CISA has published advisories covering vulnerabilities in products from CareCam, Tycon Systems, Pyramid Solutions, Inductive Automation, IXON, OPC Foundation, Ebyte, All-Line Equipment Company, Applied Systems Engineering, Xiiaozet, Furuno, Bendix, PayRange, Rently, Johnson Controls, Flow Neuroscience, Andritz, Hitachi Energy, Haiwell, Pulsetto Vagus, and Mira Hormone.
ICS Patch Tuesday September 2026: Vulnerabilities Fixed by Schneider Electric, Siemens, Aveva
Critical vulnerabilities in Schneider Electric and Siemens products could enable unauthorized access, remote code execution and complete system compromise.
Trump Declares National Emergency Over Foreign Threats to US Power Grid
New executive order gives the Energy Department broad authority to restrict, isolate, or replace foreign-sourced grid equipment over cyber sabotage and supply chain concerns.
Andrew McClure Named Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER)
McClure will oversee efforts to harden critical infrastructure, strengthen preparedness and emergency response capabilities, and build partnerships across federal, state, local, and private-sector stakeholders.
Coordinated Cyberattacks Hit Dozens of Minnesota Water Utilities, Raising Questions of Link to T-Mobile Outage
State and federal agencies are investigating intrusions that disrupted automated controls at municipal water and wastewater systems, and some OT experts are asking whether the attacks were timed to coincide with the same-day T-Mobile 5G outage.
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
Independently judged. Sponsor-neutral. Winners announced live at the 2026 ICS Cybersecurity Conference.
Accenture Places $4.1 Billion Bet on OT Cybersecurity
Accenture to will acquire a majority stake in OT security firm Dragos, and fully acquire runZero and NetRise in $4.1 billion OT cybersecurity push.
Podcast With Mike Holcomb: Beyond OT Visibility – Trust, Consequence, and the Next Wave of Industrial Cyber Risk
In this SecurityWeek podcast, Brian Schleifer is joined by Mike Holcomb, one of the most recognizable voices in OT and ICS cybersecurity.
ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary Edition
The 2026 ICS Cybersecurity Conference will take place October 6–8, 2026, at the W Hotel Nashville.
