Schneider Electric, Siemens, and Aveva released September 2026 Patch Tuesday advisories addressing multiple vulnerabilities in their industrial control and automation products. The updates include critical flaws such as CVE-2026-3869 in Modicon M580 controllers and CVE-2026-31431 in the Linux kernel, along with several high-severity issues across other ICS platforms. #SchneiderElectric #Siemens #Aveva #ModiconM580 #CVE-2026-3869 #CVE-2026-31431
Keypoints
- Schneider Electric published four new advisories and updated four older ones.
- CVE-2026-3869 is a critical authentication flaw in Modicon M580 and Modicon M580 Safety controllers.
- Siemens released nine new advisories and updated nine others, including critical issues in several products.
- Aveva fixed four flaws in PIMBoards and warned about unsafe deserialization in Enterprise SCADA.
- Rockwell Automation and CISA also issued multiple advisories for ICS and industrial product vulnerabilities.
Read More: https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/