Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical ICS Vulnerabilities Revealed by Siemens and Schneider

Critical ICS Vulnerabilities Revealed by Siemens and Schneider

Posted on May 13, 2026 By CWS

For the May 2026 Patch Tuesday, Siemens, Schneider Electric, CISA, and CERT@VDE have released new security advisories concerning industrial control system (ICS) vulnerabilities. These updates are crucial for protecting critical infrastructure from potential cyber threats.

Siemens Addresses Critical Security Flaws

Siemens has unveiled 18 new security advisories, several of which highlight critical vulnerabilities across their products. Key issues include device takeover in Sentron 7KT PAC1261 Data Manager and cross-site scripting (XSS) vulnerabilities in the Simatic S7 PLC web server. Additionally, Siemens noted command execution as root in Ruggedcom Rox and over 300 third-party component vulnerabilities in Simatic CN4100.

Moreover, Siemens has informed its customers about a significant vulnerability in the Ruggedcom APE1808 product related to the Palo Alto Networks PAN-OS flaw. This vulnerability is notable for being actively exploited, potentially by state-sponsored entities.

High-Severity Threats in Siemens and Schneider Products

Siemens has also rectified high-severity vulnerabilities capable of remote code execution in products such as Simcenter Femap, Teamcenter, and Ruggedcom Rox. Additionally, information disclosure risks and control panel escape issues have been mitigated in products like KACO Blueplanet inverters and Simatic HMI Unified Comfort, respectively.

Schneider Electric has released four advisories, addressing high-severity issues in their EcoStruxure Panel Server and other products. These vulnerabilities involve unauthorized file access and session hijacking, posing significant risks if left unpatched.

Additional Security Updates from CISA and CERT@VDE

The Cybersecurity and Infrastructure Security Agency (CISA) has issued advisories for vulnerabilities in various ABB products and others from Subnet Solutions, Fuji Electric, Maxhub, and Johnson Controls. These advisories aim to alert users to potential security threats and recommend necessary actions.

Germany’s CERT@VDE has highlighted a medium-severity denial of service (DoS) flaw in Codesys Modbus, emphasizing the continuous need for vigilant security practices in ICS environments.

The release of these advisories underscores the ongoing challenges in securing industrial control systems against cyberattacks. As these vulnerabilities are disclosed and addressed, organizations are urged to update their systems promptly to mitigate potential risks.

Security Week News Tags:CISA, critical infrastructure, cyber threats, Cybersecurity, ICS security, industrial control systems, Patch Tuesday, Schneider Electric, Siemens, Vulnerabilities

Post navigation

Previous Post: Microsoft’s New Update Enhances Windows 11 Security
Next Post: Top Data Loss Prevention Tools for 2026

Related Posts

Rethinking Cybersecurity for Autonomous AI Agents Rethinking Cybersecurity for Autonomous AI Agents Security Week News
German Authorities Identify REvil Ransomware Chief German Authorities Identify REvil Ransomware Chief Security Week News
Canadian Electric Utility Says Power Meters Disrupted by Cyberattack Canadian Electric Utility Says Power Meters Disrupted by Cyberattack Security Week News
EU Imposes Sanctions on Firms Linked to Cyber Attacks EU Imposes Sanctions on Firms Linked to Cyber Attacks Security Week News
OneDrive Gives Web Apps Full Read Access to All Files OneDrive Gives Web Apps Full Read Access to All Files Security Week News
JPMorgan to Invest up to  Billion in US Companies with Crucial Ties to National Security JPMorgan to Invest up to $10 Billion in US Companies with Crucial Ties to National Security Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ShinyHunters Allegedly Breaches Council of Europe
  • LiteLLM Vulnerability Allows Server Takeover
  • Microsoft Domain Faces Trust Issues Due to Expired Certificate
  • Hack Targets French Government Messaging Platform
  • Microsoft 365 Flaw Risked Email and File Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ShinyHunters Allegedly Breaches Council of Europe
  • LiteLLM Vulnerability Allows Server Takeover
  • Microsoft Domain Faces Trust Issues Due to Expired Certificate
  • Hack Targets French Government Messaging Platform
  • Microsoft 365 Flaw Risked Email and File Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark