CVE Tools

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

SecurityWeekBy Ionut Arghire

RoundupModicon M580PowerLogic T300

Our summary

Schneider Electric and Siemens have issued their September 2026 industrial control system advisories, addressing multiple high-severity defects across various hardware and software platforms. Schneider's most significant fix resolves CVE-2026-3869, a critical authentication bug with a CVSS score of 9.2 affecting Modicon M580 and Modicon M580 Safety controllers, alongside updates for PowerLogic T300 and SCADAPack x70 products. Siemens simultaneously published nine new advisories targeting critical vulnerabilities in systems such as Reyrolle 7SR5 and Open Interface Services, while also deploying patches for the Linux kernel flaw CVE-2026-31431.

Additional vendors included Aveva, which fixed hardcoded key issues in PIMBoards, and Rockwell Automation, which addressed critical flaws in RSLinx Classic and several controller modules.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store