Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact

Posted on January 15, 2026January 15, 2026 By CWS

Industrial giants Siemens, Schneider Electrical, Phoenix Contact, and Aveva have printed a dozen Patch Tuesday advisories to tell prospects about vulnerabilities discovered of their ICS/OT merchandise.

Siemens has launched 5 new advisories. Two of them describe the identical crucial authorization bypass flaw in Industrial Edge Units that may be leveraged by an unauthenticated, distant attacker to bypass authentication and impersonate a consumer. One advisory covers Industrial Edge Units, whereas the opposite is for the Industrial Edge Gadget Package.

The remaining advisories inform prospects in regards to the availability of fixes for high-severity vulnerabilities in Ruggedcom, ET 200SP, and TeleControl Server Primary merchandise.

Schneider Electrical has printed 4 new advisories. One in all them describes a high-severity problem that may be leveraged for privilege escalation in EcoStruxure Course of merchandise.

One other advisory describes one medium- and one high-severity flaw in EcoStruxure Energy Construct Rapsody. They are often exploited for arbitrary code execution utilizing specifically crafted recordsdata. 

The remaining advisories describe vulnerabilities in third-party parts utilized by Schneider Electrical merchandise, particularly Zigbee and Redis. Commercial. Scroll to proceed studying.

Phoenix Contact has launched an advisory to tell prospects a couple of high-severity command injection problem that may be exploited by an attacker in opposition to TC Router and Cloud Consumer industrial routers. Exploitation requires the attacker to have elevated privileges on the focused system, or they want trick the sufferer into importing a malicious payload.

Germany’s VDE CERT has additionally printed a model of Phoenix Contact’s advisory.

Aveva has printed an advisory describing seven kinds of vulnerabilities in Course of Optimization (previously ROMeo). The safety holes, rated excessive and significant severity, may be exploited for distant code execution, privilege escalation, and to acquire delicate knowledge. 

Honeywell has launched safety advisories for its Professional-Watch and Maxpro constructing safety and video administration merchandise. The advisories principally deal with Home windows patches launched by Microsoft.

The cybersecurity company CISA has printed ICS advisories for Rockwell Automation vulnerabilities disclosed by the seller in December 2025, in addition to for 3 flaws discovered within the YoSmart YoLink Sensible Hub.

A number of days earlier than Patch Tuesday, ABB printed an advisory to tell prospects about three flaws that may result in authentication bypass and DoS in its WebPro SNMP Card PowerValue product. 

Associated: ICS Patch Tuesday: Vulnerabilities Mounted by Siemens, Rockwell, Schneider

Associated: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider

Security Week News Tags:Aveva, Contact, Fixed, ICS, Patch, Phoenix, Schneider, Siemens, Tuesday, Vulnerabilities

Post navigation

Previous Post: Traveler Information Stolen in Eurail Data Breach
Next Post: VoidLink Linux Malware Framework Targets Cloud Environments

Related Posts

February 2026 Cybersecurity M&A: Key Deals Highlighted February 2026 Cybersecurity M&A: Key Deals Highlighted Security Week News
240,000 Impacted by Data Breach at Eyecare Tech Firm Ocuco 240,000 Impacted by Data Breach at Eyecare Tech Firm Ocuco Security Week News
Red Teams Jailbreak GPT-5 With Ease, Warn It’s ‘Nearly Unusable’ for Enterprise Red Teams Jailbreak GPT-5 With Ease, Warn It’s ‘Nearly Unusable’ for Enterprise Security Week News
AI-Driven Breach Exposes FortiGate Firewalls Globally AI-Driven Breach Exposes FortiGate Firewalls Globally Security Week News
Airport Cyberattack Disrupts More Flights Across Europe Airport Cyberattack Disrupts More Flights Across Europe Security Week News
Automotive IT Firm Hyundai AutoEver Discloses Data Breach Automotive IT Firm Hyundai AutoEver Discloses Data Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark