Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities SecurityWeek

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

The article details multiple critical and high-severity vulnerabilities patched by major ICS vendors, including a critical authentication bypass (CVE-2026-3869, CVSS 9.2) in Schneider Electric Modicon M580 controllers and a high-severity Linux kernel flaw (CVE-2026-31431, CVSS 7.8) affecting Siemens products, which allows attackers to achieve root shell access. For CVE-2026-31431, affected Linux kernel versions range from 4.14 through 6.7, with specific fixed versions provided (e.g., 5.10.254, 6.12.85). The summary advises applying vendor-specific patches immediately, as detailed in their respective September 2026 advisories.
Read Full Article →

ICS/OT ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. By Ionut Arghire | September 9, 2026 (6:49 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Industrial giants Schneider Electric, Siemens, and Aveva have published September 2026 Patch Tuesday advisories, informing customers about vulnerabilities found in their ICS products. Schneider Electric published four new security advisories and updated four others, including one originally released in 2019. The most severe of the newly addressed issues is a critical authentication vulnerability in Modicon M580 and Modicon M580 Safety controllers. Tracked as CVE-2026-3869, the flaw has a CVSS score of 9.2. Schneider Electric also resolved high-severity bugs in the PowerLogic T300 platform (formerly Easergy T300 RTU) and its EcoStruxure IT Data Center Expert product, and a medium-severity defect in SCADAPack x70 products. Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference On Tuesday, the company also updated four security advisories that cover older security weaknesses to add mentions of patches being rolled out for the Modicon MC80 controller. Advertisement. Scroll to continue reading. Siemens has published nine new advisories since the last Patch Tuesday, including seven on September 8. It also updated nine other advisories. Four of the newly released advisories cover critical-severity vulnerabilities in Reyrolle 7SR5, Open Interface Services (OIS), Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT. The remaining flaws are high-severity issues in Desigo CC, Teamcenter, Mendix SAML module, and Element Maps. Additionally, the company announced the rollout of updates for several products to resolve the Copy Fail Linux kernel vulnerability disclosed in April. Tracked as CVE-2026-31431 (CVSS score of 7.8), it allows attackers to achieve root shell access. Aveva on Tuesday published an advisory covering four flaws in the PIMBoards component of Pipeline Integrity Monitor. Two are high-severity bugs: a hardcoded encryption key allows attackers to decrypt sensitive information, and passwords being hashed with MD5 could allow attackers to reverse-engineer administrative passwords. Since the previous Patch Tuesday, Aveva also warned of a medium-severity unsafe deserialization vulnerability in Enterprise SCADA that could potentially lead to remote code execution. Last week, Rockwell Automation published nine security advisories that cover critical- and high-severity flaws in RSLinx Classic and high-severity bugs in the 1756-ENBT module, FactoryTalk Historian Machine Edition (ME), FactoryTalk Activation Manager, Redundancy Module Configuration Tool, ControlFLASH, ArmorStart Distributed Motor Controllers, and the CompactLogix 5380/5480/5580, GuardLogix 5580, and Compact GuardLogix 5380 controllers. Since the previous Patch Tuesday, CISA has published advisories for vulnerabilities in CareCam, Tycon Systems, Pyramid Solutions, Inductive Automation, IXON, OPCFoundation, Ebyte, All-Line Equipment Company, Applied Systems Engineering, Xiiaozet, Furuno, Bendix, PayRange, Rently, Johnson Controls, Flow Neuroscience, Andritz, Hitachi Energy, Haiwell, Pulsetto Vagus, and Mira Hormone products. Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire SAP Patches Critical Extended Passport Processing Vulnerability MikroTik Patches Critical Flaws Chained to Hack Routers Mathspace Data Breach Exposes Over 1 Million People N-able Patches Critical Zero-Day in N-central Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits North Korean Hackers Deploy New Linux Espionage Toolkit Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Modified ScreenConnect Clients Used in Worm-Like Campaign Latest News Ivanti Patches Critical Flaws Across Enterprise Security Products New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser This Key Will Self-Destruct: An Open Standard for Revocable API Keys Chrome 153 Patches Seventh Zero-Day of 2026 Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day The Hidden Instructions That Can Hijack AI Agents Hackers Return $263 Million Stolen From Liquid Network Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the Move Frank Verdecanna has been appointed Chief Financial Officer at Armadin. Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America. Skyhigh Security has named Anthony Palladino as Chief Operating Officer. More People On The Move Expert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email

Share this article