Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Siemens and Schneider Lead ICS Patch Tuesday Updates

Siemens and Schneider Lead ICS Patch Tuesday Updates

Posted on March 11, 2026 By CWS

Major industrial players Siemens, Schneider Electric, Mitsubishi Electric, and Moxa have released new advisories as part of the latest Patch Tuesday, addressing recently discovered vulnerabilities in their industrial control systems (ICS) products.

Schneider Electric’s Advisory Updates

Schneider Electric has issued six new advisories, each concerning distinct vulnerabilities. High-severity issues have been identified in EcoStruxure IT Data Center Expert due to hardcoded credentials, as well as in EcoStruxure Power Monitoring Expert and Power Operation, where local arbitrary code execution is possible. Furthermore, EcoStruxure Automation Expert is affected by vulnerabilities that could lead to command execution and full system compromise.

Additional medium-severity vulnerabilities have been patched in Modicon controllers, which were susceptible to denial-of-service attacks and account takeovers via cross-site scripting (XSS), and in EcoStruxure Foxboro DCS, which faced remote code execution risks.

Siemens’ Critical Vulnerability Fixes

Siemens addressed significant vulnerabilities, including a critical stored XSS flaw in Simatic S7-1500 devices and a potentially serious misconfiguration issue in Mendix applications. Moreover, Siemens notified users of vulnerabilities stemming from third-party components such as Fortinet and OpenSSL.

Other patched vulnerabilities by Siemens include high- and medium-severity issues in the Sicam Siapp SDK, while a low-severity flaw was resolved in Heliox EV chargers.

Updates from Mitsubishi Electric and Moxa

Mitsubishi Electric released a new advisory detailing a remotely exploitable denial-of-service vulnerability affecting its Numerical Control Systems, including the C80, M800, M800V, and M700V series. Earlier, the company alerted customers to several remotely exploitable DoS vulnerabilities in MELSEC iQ-F Series controllers.

Moxa announced four new advisories, with three addressing vulnerabilities found in Intel products. The fourth advisory clarified that Moxa products are unaffected by a recent GNU Inetutils vulnerability.

Broader Cybersecurity Updates

The Cybersecurity and Infrastructure Security Agency (CISA) also published ICS advisories this Patch Tuesday, highlighting vulnerabilities in Ceragon Siklu MultiHaul, Lantronix EDS3000PS and EDS5000, and Apeman cameras. Additionally, a new advisory was issued for a Honeywell building controller vulnerability, which has been the subject of a dispute regarding its impact.

Germany’s VDE-CERT released advisories for vulnerabilities in Codesys, Janitza, and Weidmueller products, some of which allow remote, unauthenticated attackers to fully compromise targeted systems.

As cyber threats in industrial environments continue to evolve, these updates underscore the critical need for organizations to promptly apply security patches to safeguard their systems.

Security Week News Tags:CISA advisories, Cybersecurity, ICS security, industrial control systems, Mitsubishi Electric, Moxa, Schneider Electric, Siemens

Post navigation

Previous Post: Critical Gogs Flaw Allows Silent Overwriting of LFS Objects
Next Post: Critical Microsoft .NET Vulnerability Demands Immediate Attention

Related Posts

Critical Vulnerability Threatens 300,000 Ollama Deployments Critical Vulnerability Threatens 300,000 Ollama Deployments Security Week News
Former CISA Director Jen Easterly Appointed CEO of RSAC Former CISA Director Jen Easterly Appointed CEO of RSAC Security Week News
Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms Security Week News
Network Security Challenges: No Exploits Needed Network Security Challenges: No Exploits Needed Security Week News
Romanian Extradited to US Over Decade-Old Cybercrime Romanian Extradited to US Over Decade-Old Cybercrime Security Week News
Northwest Radiologists Data Breach Impacts 350,000 Washingtonians Northwest Radiologists Data Breach Impacts 350,000 Washingtonians Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Rockwell Fixes Critical Flaws in Arena Software
  • GitLab RCE Exploit Allows Command Execution as Git
  • Critical Foxit Vulnerability Allows SYSTEM Privilege Escalation
  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Rockwell Fixes Critical Flaws in Arena Software
  • GitLab RCE Exploit Allows Command Execution as Git
  • Critical Foxit Vulnerability Allows SYSTEM Privilege Escalation
  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark