Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Siemens and Schneider Lead ICS Patch Tuesday Updates

Siemens and Schneider Lead ICS Patch Tuesday Updates

Posted on March 11, 2026 By CWS

Major industrial players Siemens, Schneider Electric, Mitsubishi Electric, and Moxa have released new advisories as part of the latest Patch Tuesday, addressing recently discovered vulnerabilities in their industrial control systems (ICS) products.

Schneider Electric’s Advisory Updates

Schneider Electric has issued six new advisories, each concerning distinct vulnerabilities. High-severity issues have been identified in EcoStruxure IT Data Center Expert due to hardcoded credentials, as well as in EcoStruxure Power Monitoring Expert and Power Operation, where local arbitrary code execution is possible. Furthermore, EcoStruxure Automation Expert is affected by vulnerabilities that could lead to command execution and full system compromise.

Additional medium-severity vulnerabilities have been patched in Modicon controllers, which were susceptible to denial-of-service attacks and account takeovers via cross-site scripting (XSS), and in EcoStruxure Foxboro DCS, which faced remote code execution risks.

Siemens’ Critical Vulnerability Fixes

Siemens addressed significant vulnerabilities, including a critical stored XSS flaw in Simatic S7-1500 devices and a potentially serious misconfiguration issue in Mendix applications. Moreover, Siemens notified users of vulnerabilities stemming from third-party components such as Fortinet and OpenSSL.

Other patched vulnerabilities by Siemens include high- and medium-severity issues in the Sicam Siapp SDK, while a low-severity flaw was resolved in Heliox EV chargers.

Updates from Mitsubishi Electric and Moxa

Mitsubishi Electric released a new advisory detailing a remotely exploitable denial-of-service vulnerability affecting its Numerical Control Systems, including the C80, M800, M800V, and M700V series. Earlier, the company alerted customers to several remotely exploitable DoS vulnerabilities in MELSEC iQ-F Series controllers.

Moxa announced four new advisories, with three addressing vulnerabilities found in Intel products. The fourth advisory clarified that Moxa products are unaffected by a recent GNU Inetutils vulnerability.

Broader Cybersecurity Updates

The Cybersecurity and Infrastructure Security Agency (CISA) also published ICS advisories this Patch Tuesday, highlighting vulnerabilities in Ceragon Siklu MultiHaul, Lantronix EDS3000PS and EDS5000, and Apeman cameras. Additionally, a new advisory was issued for a Honeywell building controller vulnerability, which has been the subject of a dispute regarding its impact.

Germany’s VDE-CERT released advisories for vulnerabilities in Codesys, Janitza, and Weidmueller products, some of which allow remote, unauthenticated attackers to fully compromise targeted systems.

As cyber threats in industrial environments continue to evolve, these updates underscore the critical need for organizations to promptly apply security patches to safeguard their systems.

Security Week News Tags:CISA advisories, Cybersecurity, ICS security, industrial control systems, Mitsubishi Electric, Moxa, Schneider Electric, Siemens

Post navigation

Previous Post: Critical Gogs Flaw Allows Silent Overwriting of LFS Objects
Next Post: Critical Microsoft .NET Vulnerability Demands Immediate Attention

Related Posts

Open Source CISA Tool Helps Defenders With Hacker Containment, Eviction Open Source CISA Tool Helps Defenders With Hacker Containment, Eviction Security Week News
Pierce County Library Data Breach Impacts 340,000 Pierce County Library Data Breach Impacts 340,000 Security Week News
Qantas Confirms 5.7 Million Impacted by Data Breach Qantas Confirms 5.7 Million Impacted by Data Breach Security Week News
Google Offers Up to ,000 in New AI Bug Bounty Program Google Offers Up to $20,000 in New AI Bug Bounty Program Security Week News
Critical Triofox Vulnerability Exploited in the Wild Critical Triofox Vulnerability Exploited in the Wild Security Week News
Hackers Access Legacy Systems in Oxford City Council Cyberattack Hackers Access Legacy Systems in Oxford City Council Cyberattack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Instagram Outage Disrupts Global User Access and Messaging
  • Michelin Acknowledges Data Breach from Oracle EBS Attack
  • BlackSanta Malware Disables Security Before Attack
  • Microsoft Fixes 84 Security Flaws, Including Two Zero-Days
  • UNC6426 Leverages npm Flaw for Rapid AWS Admin Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Instagram Outage Disrupts Global User Access and Messaging
  • Michelin Acknowledges Data Breach from Oracle EBS Attack
  • BlackSanta Malware Disables Security Before Attack
  • Microsoft Fixes 84 Security Flaws, Including Two Zero-Days
  • UNC6426 Leverages npm Flaw for Rapid AWS Admin Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News