Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Siemens and Schneider Lead ICS Patch Tuesday Updates

Siemens and Schneider Lead ICS Patch Tuesday Updates

Posted on March 11, 2026 By CWS

Major industrial players Siemens, Schneider Electric, Mitsubishi Electric, and Moxa have released new advisories as part of the latest Patch Tuesday, addressing recently discovered vulnerabilities in their industrial control systems (ICS) products.

Schneider Electric’s Advisory Updates

Schneider Electric has issued six new advisories, each concerning distinct vulnerabilities. High-severity issues have been identified in EcoStruxure IT Data Center Expert due to hardcoded credentials, as well as in EcoStruxure Power Monitoring Expert and Power Operation, where local arbitrary code execution is possible. Furthermore, EcoStruxure Automation Expert is affected by vulnerabilities that could lead to command execution and full system compromise.

Additional medium-severity vulnerabilities have been patched in Modicon controllers, which were susceptible to denial-of-service attacks and account takeovers via cross-site scripting (XSS), and in EcoStruxure Foxboro DCS, which faced remote code execution risks.

Siemens’ Critical Vulnerability Fixes

Siemens addressed significant vulnerabilities, including a critical stored XSS flaw in Simatic S7-1500 devices and a potentially serious misconfiguration issue in Mendix applications. Moreover, Siemens notified users of vulnerabilities stemming from third-party components such as Fortinet and OpenSSL.

Other patched vulnerabilities by Siemens include high- and medium-severity issues in the Sicam Siapp SDK, while a low-severity flaw was resolved in Heliox EV chargers.

Updates from Mitsubishi Electric and Moxa

Mitsubishi Electric released a new advisory detailing a remotely exploitable denial-of-service vulnerability affecting its Numerical Control Systems, including the C80, M800, M800V, and M700V series. Earlier, the company alerted customers to several remotely exploitable DoS vulnerabilities in MELSEC iQ-F Series controllers.

Moxa announced four new advisories, with three addressing vulnerabilities found in Intel products. The fourth advisory clarified that Moxa products are unaffected by a recent GNU Inetutils vulnerability.

Broader Cybersecurity Updates

The Cybersecurity and Infrastructure Security Agency (CISA) also published ICS advisories this Patch Tuesday, highlighting vulnerabilities in Ceragon Siklu MultiHaul, Lantronix EDS3000PS and EDS5000, and Apeman cameras. Additionally, a new advisory was issued for a Honeywell building controller vulnerability, which has been the subject of a dispute regarding its impact.

Germany’s VDE-CERT released advisories for vulnerabilities in Codesys, Janitza, and Weidmueller products, some of which allow remote, unauthenticated attackers to fully compromise targeted systems.

As cyber threats in industrial environments continue to evolve, these updates underscore the critical need for organizations to promptly apply security patches to safeguard their systems.

Security Week News Tags:CISA advisories, Cybersecurity, ICS security, industrial control systems, Mitsubishi Electric, Moxa, Schneider Electric, Siemens

Post navigation

Previous Post: Critical Gogs Flaw Allows Silent Overwriting of LFS Objects
Next Post: Critical Microsoft .NET Vulnerability Demands Immediate Attention

Related Posts

University of Sydney Data Breach Affects 27,000 Individuals  University of Sydney Data Breach Affects 27,000 Individuals  Security Week News
US Sanctions Philippine Company for Supporting Crypto Scams US Sanctions Philippine Company for Supporting Crypto Scams Security Week News
CISA Expands KEV List with iOS Vulnerability Additions CISA Expands KEV List with iOS Vulnerability Additions Security Week News
Over 73,000 WatchGuard Firebox Devices Impacted by Recent Critical Flaw Over 73,000 WatchGuard Firebox Devices Impacted by Recent Critical Flaw Security Week News
Cisco Addresses Critical Security Flaws in Networking Gear Cisco Addresses Critical Security Flaws in Networking Gear Security Week News
AI Advances Cyber Threats, But Identity Remains Key AI Advances Cyber Threats, But Identity Remains Key Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CyberCheck360: Advancing Email Security Beyond Gateways
  • Critical FortiSandbox Flaw Allows Remote Command Execution
  • Optimize SOC Efficiency with Threat Intelligence Feeds
  • Critical Flaw in Veeam Poses RCE Threat to Servers
  • Microsoft Fixes 200 Flaws in June Patch Tuesday

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CyberCheck360: Advancing Email Security Beyond Gateways
  • Critical FortiSandbox Flaw Allows Remote Command Execution
  • Optimize SOC Efficiency with Threat Intelligence Feeds
  • Critical Flaw in Veeam Poses RCE Threat to Servers
  • Microsoft Fixes 200 Flaws in June Patch Tuesday

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark