Siemens, Schneider Electric, Phoenix Contact, Honeywell, and CISA released August 2026 advisories for multiple ICS and building management product vulnerabilities, including code execution, privilege escalation, and denial-of-service flaws. The most severe issues affect Siemens Simatic IoT2050 Advanced and Siveillance Video Management Servers, while Phoenix Contact and Schneider Electric also patched critical weaknesses in PLCnext firmware, NetBotz 5, and PowerChute Serial Shutdown. #Siemens #SchneiderElectric #PhoenixContact #Honeywell #CISA #SimaticIoT2050Advanced #SiveillanceVideoManagementServers #PLCnext #NetBotz5 #PowerChuteSerialShutdown
Keypoints
- Siemens issued 10 advisories for vulnerabilities across multiple ICS products.
- A missing-authentication flaw in Simatic IoT2050 Advanced can lead to remote code execution.
- Siemens also fixed a critical code execution issue in Siveillance Video Management Servers.
- Schneider Electric patched code execution issues in NetBotz 5 and an authentication flaw in PowerChute Serial Shutdown.
- Phoenix Contact, Honeywell, and CISA also released advisories for PLCnext firmware, building management systems, and other products.