Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical ICS Vulnerabilities Revealed by Siemens and Schneider

Critical ICS Vulnerabilities Revealed by Siemens and Schneider

Posted on May 13, 2026 By CWS

For the May 2026 Patch Tuesday, Siemens, Schneider Electric, CISA, and CERT@VDE have released new security advisories concerning industrial control system (ICS) vulnerabilities. These updates are crucial for protecting critical infrastructure from potential cyber threats.

Siemens Addresses Critical Security Flaws

Siemens has unveiled 18 new security advisories, several of which highlight critical vulnerabilities across their products. Key issues include device takeover in Sentron 7KT PAC1261 Data Manager and cross-site scripting (XSS) vulnerabilities in the Simatic S7 PLC web server. Additionally, Siemens noted command execution as root in Ruggedcom Rox and over 300 third-party component vulnerabilities in Simatic CN4100.

Moreover, Siemens has informed its customers about a significant vulnerability in the Ruggedcom APE1808 product related to the Palo Alto Networks PAN-OS flaw. This vulnerability is notable for being actively exploited, potentially by state-sponsored entities.

High-Severity Threats in Siemens and Schneider Products

Siemens has also rectified high-severity vulnerabilities capable of remote code execution in products such as Simcenter Femap, Teamcenter, and Ruggedcom Rox. Additionally, information disclosure risks and control panel escape issues have been mitigated in products like KACO Blueplanet inverters and Simatic HMI Unified Comfort, respectively.

Schneider Electric has released four advisories, addressing high-severity issues in their EcoStruxure Panel Server and other products. These vulnerabilities involve unauthorized file access and session hijacking, posing significant risks if left unpatched.

Additional Security Updates from CISA and CERT@VDE

The Cybersecurity and Infrastructure Security Agency (CISA) has issued advisories for vulnerabilities in various ABB products and others from Subnet Solutions, Fuji Electric, Maxhub, and Johnson Controls. These advisories aim to alert users to potential security threats and recommend necessary actions.

Germany’s CERT@VDE has highlighted a medium-severity denial of service (DoS) flaw in Codesys Modbus, emphasizing the continuous need for vigilant security practices in ICS environments.

The release of these advisories underscores the ongoing challenges in securing industrial control systems against cyberattacks. As these vulnerabilities are disclosed and addressed, organizations are urged to update their systems promptly to mitigate potential risks.

Security Week News Tags:CISA, critical infrastructure, cyber threats, Cybersecurity, ICS security, industrial control systems, Patch Tuesday, Schneider Electric, Siemens, Vulnerabilities

Post navigation

Previous Post: Microsoft’s New Update Enhances Windows 11 Security
Next Post: Top Data Loss Prevention Tools for 2026

Related Posts

Nippon Steel Subsidiary Blames Data Breach on Zero-Day Attack Nippon Steel Subsidiary Blames Data Breach on Zero-Day Attack Security Week News
Chinese Researchers Suggest Lasers and Sabotage to Counter Musk’s Starlink Satellites Chinese Researchers Suggest Lasers and Sabotage to Counter Musk’s Starlink Satellites Security Week News
RMPocalypse: New Attack Breaks AMD Confidential Computing RMPocalypse: New Attack Breaks AMD Confidential Computing Security Week News
Over 300,000 Individuals Impacted by Vitas Hospice Data Breach Over 300,000 Individuals Impacted by Vitas Hospice Data Breach Security Week News
Spektrum Labs Emerges From Stealth to Help Companies Prove Resilience Spektrum Labs Emerges From Stealth to Help Companies Prove Resilience Security Week News
Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Data Loss Prevention Tools for 2026
  • Critical ICS Vulnerabilities Revealed by Siemens and Schneider
  • Microsoft’s New Update Enhances Windows 11 Security
  • Critical Microsoft Teams Flaw Allows Device Spoofing
  • Critical SQL Injection Flaw Patched in SAP S/4HANA

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Data Loss Prevention Tools for 2026
  • Critical ICS Vulnerabilities Revealed by Siemens and Schneider
  • Microsoft’s New Update Enhances Windows 11 Security
  • Critical Microsoft Teams Flaw Allows Device Spoofing
  • Critical SQL Injection Flaw Patched in SAP S/4HANA

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark