ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

https://www.securityweek.com/wp-content/uploads/2024/06/PLC-HMI-SCADA-ICS-industrial.jpeg

Industrial giants Schneider Electric, Siemens, and Aveva have published September 2026 Patch Tuesday advisories, informing customers about vulnerabilities found in their ICS products.

Schneider Electric published four new security advisories and updated four others, including one originally released in 2019.

The most severe of the newly addressed issues is a critical authentication vulnerability in Modicon M580 and Modicon M580 Safety controllers. Tracked as CVE-2026-3869, the flaw has a CVSS score of 9.2.

Schneider Electric also resolved high-severity bugs in the PowerLogic T300 platform (formerly Easergy T300 RTU) and its EcoStruxure IT Data Center Expert product, and a medium-severity defect in SCADAPack x70 products.

Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference

On Tuesday, the company also updated four security advisories that cover older security weaknesses to add mentions of patches being rolled out for the Modicon MC80 controller.

Advertisement. Scroll to continue reading.

Siemenshas published nine new advisories since...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more