Wednesday, 07 October 2026

Schneider Electric and Siemens Fix Critical Flaws

Schneider Electric, Siemens, and Aveva released their September 2026 Patch Tuesday advisories, addressing multiple vulnerabilities in industrial control system (ICS) products.

Schneider Electric's most serious fix targets a critical authentication flaw in its Modicon M580 and Modicon M580 Safety controllers (CVE-2026-3869, CVSS 9.2), along with high-severity issues in its PowerLogic T300 platform and EcoStruxure IT Data Center Expert.

Siemens published nine new advisories covering four critical vulnerabilities — including flaws in Reyrolle 7SR5, its Open Interface Services, Industrial Edge Management,  SIMOVE Fleetmanager and SIPLANT products — plus several high-severity bugs. It also rolled out fixes tied to the previously disclosed "Copy Fail" Linux kernel vulnerability (CVE-2026-31431), which could let to gain root access.

Aveva addressed flaws in its Pipeline Integrity Monitor component, including a hardcoded encryption key and weak password hashing that could expose admin credentials.

Rockwell Automation has also issued nine advisories, covering critical and high-severity issues across several of its products.

Source: securityweek.com

14 September 2026

-
77