Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical ICS Vulnerabilities Patched by Schneider and Siemens

Critical ICS Vulnerabilities Patched by Schneider and Siemens

Posted on September 9, 2026 By CWS

In a significant cybersecurity update, leading industrial firms Schneider Electric, Siemens, and Aveva have issued advisories as part of the September 2026 Patch Tuesday. These advisories address various vulnerabilities found in their Industrial Control Systems (ICS) products.

Schneider Electric’s Security Updates

Schneider Electric has released four new advisories and updated four existing ones, including one from 2019. Among the newly disclosed issues, a critical authentication vulnerability in the Modicon M580 and Modicon M580 Safety controllers stands out, marked as CVE-2026-3869 with a CVSS score of 9.2. The company has also resolved high-severity vulnerabilities in the PowerLogic T300 platform and EcoStruxure IT Data Center Expert, along with a medium-severity flaw in SCADAPack x70 products.

Siemens’ Patch Releases

Since the last Patch Tuesday, Siemens has introduced nine new advisories and updated nine others. Four of the new advisories address critical-severity vulnerabilities in products such as Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT. Additionally, Siemens has rolled out updates to fix the Copy Fail Linux kernel vulnerability, identified as CVE-2026-31431 with a CVSS score of 7.8, which could potentially grant root shell access to attackers.

Aveva’s Advisory on Pipeline Integrity Monitor

Aveva has also contributed to the Patch Tuesday efforts by issuing an advisory for four vulnerabilities within the Pipeline Integrity Monitor’s PIMBoards component. Notably, two high-severity flaws involve a hardcoded encryption key issue and MD5 password hashing that may allow attackers to reverse-engineer administrative passwords. Furthermore, Aveva highlighted a medium-severity deserialization vulnerability in Enterprise SCADA, which poses a risk of remote code execution.

Additionally, Rockwell Automation and other companies like CISA have been active in patching vulnerabilities. Rockwell has published advisories for critical and high-severity flaws across several products, while CISA has issued warnings for vulnerabilities affecting a range of products from various manufacturers.

These updates underline the ongoing efforts of industrial companies to safeguard ICS products against emerging cybersecurity threats. As vulnerabilities are discovered and patched, staying informed about these updates remains crucial for protecting critical infrastructure.

Security Week News Tags:critical flaws, Cybersecurity, ICS, industrial systems, Patch Tuesday, Schneider Electric, security patches, September 2026, Siemens, Vulnerabilities

Post navigation

Previous Post: F5 BIG-IP APM Malware Hides PHP Web Shell in Memory
Next Post: New Windows BitLocker Flaw Allows Remote Code Execution

Related Posts

Red Hat Confirms GitLab Instance Hack, Data Theft Red Hat Confirms GitLab Instance Hack, Data Theft Security Week News
Google Patches High-Severity Chrome Vulnerability in Latest Update Google Patches High-Severity Chrome Vulnerability in Latest Update Security Week News
US Calls Reported Threats by Pro-Iran Hackers to Release Trump-Tied Material a ‘Smear Campaign’ US Calls Reported Threats by Pro-Iran Hackers to Release Trump-Tied Material a ‘Smear Campaign’ Security Week News
Critical Joomla Extension Flaws Exploited Critical Joomla Extension Flaws Exploited Security Week News
New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs  New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs  Security Week News
Nutex Health Confirms Data Breach by Ransomware Group Nutex Health Confirms Data Breach by Ransomware Group Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Use Google Sheets in Crypto Wallet Attacks
  • Advanced Phishing Tactics Exploit Victim Browsers
  • DeepSeek Harness Flaw Allows AI Sandbox Bypass
  • New Windows BitLocker Flaw Allows Remote Code Execution
  • Critical ICS Vulnerabilities Patched by Schneider and Siemens

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Use Google Sheets in Crypto Wallet Attacks
  • Advanced Phishing Tactics Exploit Victim Browsers
  • DeepSeek Harness Flaw Allows AI Sandbox Bypass
  • New Windows BitLocker Flaw Allows Remote Code Execution
  • Critical ICS Vulnerabilities Patched by Schneider and Siemens

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark