In a significant cybersecurity update, leading industrial firms Schneider Electric, Siemens, and Aveva have issued advisories as part of the September 2026 Patch Tuesday. These advisories address various vulnerabilities found in their Industrial Control Systems (ICS) products.
Schneider Electric’s Security Updates
Schneider Electric has released four new advisories and updated four existing ones, including one from 2019. Among the newly disclosed issues, a critical authentication vulnerability in the Modicon M580 and Modicon M580 Safety controllers stands out, marked as CVE-2026-3869 with a CVSS score of 9.2. The company has also resolved high-severity vulnerabilities in the PowerLogic T300 platform and EcoStruxure IT Data Center Expert, along with a medium-severity flaw in SCADAPack x70 products.
Siemens’ Patch Releases
Since the last Patch Tuesday, Siemens has introduced nine new advisories and updated nine others. Four of the new advisories address critical-severity vulnerabilities in products such as Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT. Additionally, Siemens has rolled out updates to fix the Copy Fail Linux kernel vulnerability, identified as CVE-2026-31431 with a CVSS score of 7.8, which could potentially grant root shell access to attackers.
Aveva’s Advisory on Pipeline Integrity Monitor
Aveva has also contributed to the Patch Tuesday efforts by issuing an advisory for four vulnerabilities within the Pipeline Integrity Monitor’s PIMBoards component. Notably, two high-severity flaws involve a hardcoded encryption key issue and MD5 password hashing that may allow attackers to reverse-engineer administrative passwords. Furthermore, Aveva highlighted a medium-severity deserialization vulnerability in Enterprise SCADA, which poses a risk of remote code execution.
Additionally, Rockwell Automation and other companies like CISA have been active in patching vulnerabilities. Rockwell has published advisories for critical and high-severity flaws across several products, while CISA has issued warnings for vulnerabilities affecting a range of products from various manufacturers.
These updates underline the ongoing efforts of industrial companies to safeguard ICS products against emerging cybersecurity threats. As vulnerabilities are discovered and patched, staying informed about these updates remains crucial for protecting critical infrastructure.
