Industrial giants Schneider Electric, Siemens and Aveva have released September 2026 Patch Tuesday notes informing customers of vulnerabilities in their ICS products.
Schneider Electric has published four new safety advisories and updated four others, including one originally published in 2019.
The most serious of the newly fixed issues is a critical authentication vulnerability in Modicon M580 and Modicon M580 Safety controllers. The bug, tracked as CVE-2026-3869, has a CVSS score of 9.2.
Schneider Electric also fixed high-severity bugs in the PowerLogic T300 platform (formerly Easergy T300 RTU) and its EcoStruxure IT Data Center Expert product, as well as a moderate-severity bug in SCADAPack x70 products.
Practical cyber-physical systems training at the ICS Cybersecurity Conference
On Tuesday, the company also updated four security advisories covering older vulnerabilities to add notices about rolling out patches for the Modicon MC80 controller.
Siemens has released nine new advisories since the last Patch Tuesday, including seven on September 8th. In addition, nine additional advisories were updated.
Four of the newly published security advisories address critical vulnerabilities in Reyrolle 7SR5, Open Interface Services (OIS), Industrial Edge Management as well as SIMOVE Fleetmanager and SIPLANT.
The remaining bugs are high-severity issues in Desigo CC, Teamcenter, the Mendix SAML module, and Element Maps.
In addition, the company announced the rollout of updates for several products to address the “Copy Fail” vulnerability in the Linux kernel that became known in April. It is tracked as CVE-2026-31431 (CVSS score of 7.8) and allows attackers to access the root shell.
I had released an advisory on Tuesday covering four deficiencies in the PIMBoards component of Pipeline Integrity Monitor. Two of these are serious flaws: a hard-coded encryption key allows attackers to decrypt sensitive information, and passwords hashed using MD5 could allow attackers to reverse engineer administrative passwords.
Since the last Patch Tuesday, Aveva also warned of a moderate insecure deserialization vulnerability in Enterprise SCADA that could potentially lead to remote code execution.
Last week, Rockwell Automation published nine security advisories covering critical and fatal errors in RSLinx Classic, as well as fatal errors in the 1756-ENBT module, FactoryTalk Historian Machine Edition (ME), FactoryTalk Activation Manager, Redundancy Module Configuration Tool, ControlFLASH, ArmorStart distributed motor controllers, and CompactLogix 5380/5480/5580, GuardLogix 5580, and Compact GuardLogix 5380 controllers.
Since the last patch Tuesday CISA has published notices of vulnerabilities in the products CareCam, Tycon Systems, Pyramid Solutions, Inductive Automation, IXON, OPCFoundation, Ebyte, All-Line Equipment Company, Applied Systems Engineering, Xiiaozet, Furuno, Bendix, PayRange, Rently, Johnson Controls, Flow Neuroscience, Andritz, Hitachi Energy, Haiwell, Pulsetto Vagus and Mira Hormone.

Related: ICS Patch Tuesday: Vulnerabilities fixed by Siemens, Schneider, Phoenix Contact
Related: ICS Patch Tuesday: Vulnerabilities fixed by Siemens, Schneider, Rockwell
