ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
Schneider Electric and Siemens have issued their September 2026 industrial control system advisories, addressing multiple high-severity defects across various hardware and software platforms. Schneider's most significant fix resolves CVE-2026-3869, a critical authentication bug with a CVSS score of 9.2 affecting Modicon M580 and Modicon M580 Safety controllers, alongside updates for PowerLogic T300 and SCADAPack x70 products. Siemens simultaneously published nine new advisories targeting critical vulnerabilities in systems such as Reyrolle 7SR5 and Open Interface Services, while also deploying patches for the Linux kernel flaw CVE-2026-31431.
Additional vendors included Aveva, which fixed hardcoded key issues in PIMBoards, and Rockwell Automation, which addressed critical flaws in RSLinx Classic and several controller modules.