About

Conference

SecurityWeek’s ICS Cyber Security Conference is the conference where ICS users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.

<We_can_help/>

What are you looking for?

>>September

Industrial giants Schneider Electric, Siemens and AVEVA have published their September 2026 Patch Tuesday advisories, informing customers about vulnerabilities affecting their ICS products.

Schneider Electric published four new security advisories and updated four others, including one originally released in 2019.

The most severe of the newly addressed issues is a critical authentication vulnerability in Modicon M580 and Modicon M580 Safety controllers. Tracked as CVE-2026-3869, the flaw has a CVSS score of 9.2.

Schneider Electric also resolved high-severity vulnerabilities in the PowerLogic T300 platform, formerly known as the Easergy T300 RTU, and its EcoStruxure IT Data Center Expert product, as well as a medium-severity flaw affecting SCADAPack x70 products.

The company also updated four advisories covering older vulnerabilities to note the availability of patches for the Modicon MC80 controller.

Siemens has published nine new advisories since the previous Patch Tuesday, including seven released on September 8, and updated nine others.

Four of the new advisories cover critical-severity vulnerabilities affecting Reyrolle 7SR5, Open Interface Services (OIS), Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT.

The remaining advisories address high-severity vulnerabilities in Desigo CC, Teamcenter, the Mendix SAML module, and Element Maps.

Siemens also announced updates for several products affected by the Copy Fail Linux kernel vulnerability disclosed in April. Tracked as CVE-2026-31431 and carrying a CVSS score of 7.8, the flaw can allow attackers to obtain root shell access.

AVEVA published an advisory on Tuesday covering four vulnerabilities in the PIMBoards component of Pipeline Integrity Monitor.

Two are high-severity flaws: one involves a hardcoded encryption key that could allow attackers to decrypt sensitive information, while the other involves the use of MD5 for password hashing, potentially enabling attackers to recover administrative passwords.

Since the previous Patch Tuesday, AVEVA has also warned customers about a medium-severity unsafe deserialization vulnerability in Enterprise SCADA that could potentially lead to remote code execution.

Last week, Rockwell Automation published nine advisories covering critical- and high-severity vulnerabilities in RSLinx Classic, as well as high-severity flaws affecting the 1756-ENBT module, FactoryTalk Historian Machine Edition (ME), FactoryTalk Activation Manager, Redundancy Module Configuration Tool, ControlFLASH, ArmorStart Distributed Motor Controllers, and CompactLogix 5380, 5480 and 5580, GuardLogix 5580, and Compact GuardLogix 5380 controllers.

Since the previous Patch Tuesday, CISA has published advisories covering vulnerabilities in products from CareCam, Tycon Systems, Pyramid Solutions, Inductive Automation, IXON, OPC Foundation, Ebyte, All-Line Equipment Company, Applied Systems Engineering, Xiiaozet, Furuno, Bendix, PayRange, Rently, Johnson Controls, Flow Neuroscience, Andritz, Hitachi Energy, Haiwell, Pulsetto Vagus, and Mira Hormone.