ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
Schneider Electric, Siemens, and Aveva released September 2026 Patch Tuesday advisories addressing multiple vulnerabilities in their industrial control and automation products. The updates include critical flaws such as CVE-2026-3869 in Modicon M580 controllers and CVE-2026-31431 in the Linux kernel, along with several high-severity issues across other ICS platforms. #SchneiderElectric #Siemens #Aveva #ModiconM580 #CVE-2026-3869 #CVE-2026-31431

Keypoints

  • Schneider Electric published four new advisories and updated four older ones.
  • CVE-2026-3869 is a critical authentication flaw in Modicon M580 and Modicon M580 Safety controllers.
  • Siemens released nine new advisories and updated nine others, including critical issues in several products.
  • Aveva fixed four flaws in PIMBoards and warned about unsafe deserialization in Enterprise SCADA.
  • Rockwell Automation and CISA also issued multiple advisories for ICS and industrial product vulnerabilities.

Read More: https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/