Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact

Posted on January 15, 2026January 15, 2026 By CWS

Industrial giants Siemens, Schneider Electrical, Phoenix Contact, and Aveva have printed a dozen Patch Tuesday advisories to tell prospects about vulnerabilities discovered of their ICS/OT merchandise.

Siemens has launched 5 new advisories. Two of them describe the identical crucial authorization bypass flaw in Industrial Edge Units that may be leveraged by an unauthenticated, distant attacker to bypass authentication and impersonate a consumer. One advisory covers Industrial Edge Units, whereas the opposite is for the Industrial Edge Gadget Package.

The remaining advisories inform prospects in regards to the availability of fixes for high-severity vulnerabilities in Ruggedcom, ET 200SP, and TeleControl Server Primary merchandise.

Schneider Electrical has printed 4 new advisories. One in all them describes a high-severity problem that may be leveraged for privilege escalation in EcoStruxure Course of merchandise.

One other advisory describes one medium- and one high-severity flaw in EcoStruxure Energy Construct Rapsody. They are often exploited for arbitrary code execution utilizing specifically crafted recordsdata. 

The remaining advisories describe vulnerabilities in third-party parts utilized by Schneider Electrical merchandise, particularly Zigbee and Redis. Commercial. Scroll to proceed studying.

Phoenix Contact has launched an advisory to tell prospects a couple of high-severity command injection problem that may be exploited by an attacker in opposition to TC Router and Cloud Consumer industrial routers. Exploitation requires the attacker to have elevated privileges on the focused system, or they want trick the sufferer into importing a malicious payload.

Germany’s VDE CERT has additionally printed a model of Phoenix Contact’s advisory.

Aveva has printed an advisory describing seven kinds of vulnerabilities in Course of Optimization (previously ROMeo). The safety holes, rated excessive and significant severity, may be exploited for distant code execution, privilege escalation, and to acquire delicate knowledge. 

Honeywell has launched safety advisories for its Professional-Watch and Maxpro constructing safety and video administration merchandise. The advisories principally deal with Home windows patches launched by Microsoft.

The cybersecurity company CISA has printed ICS advisories for Rockwell Automation vulnerabilities disclosed by the seller in December 2025, in addition to for 3 flaws discovered within the YoSmart YoLink Sensible Hub.

A number of days earlier than Patch Tuesday, ABB printed an advisory to tell prospects about three flaws that may result in authentication bypass and DoS in its WebPro SNMP Card PowerValue product. 

Associated: ICS Patch Tuesday: Vulnerabilities Mounted by Siemens, Rockwell, Schneider

Associated: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider

Security Week News Tags:Aveva, Contact, Fixed, ICS, Patch, Phoenix, Schneider, Siemens, Tuesday, Vulnerabilities

Post navigation

Previous Post: Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login
Next Post: VoidLink Linux Malware Framework Targets Cloud Environments

Related Posts

Zyxel Firewall Vulnerability Again in Attacker Crosshairs Security Week News
China-Linked Hackers Hijack Web Traffic to Deliver Backdoor Security Week News
Data Breach at Healthcare Services Firm Episource Impacts 5.4 Million People Security Week News
Five Zero-Days, 15 Misconfigurations Found in Salesforce Industry Cloud Security Week News
Myanmar Military Shuts Down Major Cybercrime Center and Detains Over 2,000 People Security Week News
Hackers Stole 300,000 Crash Reports From Texas Department of Transportation Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Central Maine Healthcare Data Breach Impacts 145,000 Individuals
  • HPE Aruba Vulnerabilities Enables Unauthorized Access to Sensitive Information
  • Microsoft Legal Action Disrupts RedVDS Cybercrime Infrastructure Used for Online Fraud
  • VoidLink Linux Malware Framework Targets Cloud Environments
  • ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Central Maine Healthcare Data Breach Impacts 145,000 Individuals
  • HPE Aruba Vulnerabilities Enables Unauthorized Access to Sensitive Information
  • Microsoft Legal Action Disrupts RedVDS Cybercrime Infrastructure Used for Online Fraud
  • VoidLink Linux Malware Framework Targets Cloud Environments
  • ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark