ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
Schneider Electric disclosed a critical CVE-2026-3869 (CVSS 9.2) authentication flaw in Modicon M580/M580 Safety controllers, alongside high-severity bugs in PowerLogic T300 and EcoStruxure IT Data Center Expert, plus medium-severity issues in SCADAPack x70 Siemens released nine new advisories covering critical vulnerabilities in Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, and SIMOVE Fleetmanager/SIPLANT, plus high-severity flaws in Desigo CC, Teamcenter, and Mendix SAML
Analysis
TL;DR
- Schneider Electric disclosed a critical CVE-2026-3869 (CVSS 9.2) authentication flaw in Modicon M580/M580 Safety controllers, alongside high-severity bugs in PowerLogic T300 and EcoStruxure IT Data Center Expert, plus medium-severity issues in SCADAPack x70
- Siemens released nine new advisories covering critical vulnerabilities in Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, and SIMOVE Fleetmanager/SIPLANT, plus high-severity flaws in Desigo CC, Teamcenter, and Mendix SAML module
- Aveva published advisories for hardcoded encryption keys and MD5 password hashing in Pipeline Integrity Monitor's PIMBoards component, plus a medium-severity unsafe deserialization vulnerability in Enterprise SCADA
- Rockwell Automation issued nine advisories covering critical/high-severity flaws across RSLinx Classic, 1756-ENBT module, FactoryTalk suite, and multiple CompactLogix/GuardLogix controller lines
- CISA released advisories spanning 20+ vendors including Inductive Automation, OPC Foundation, Johnson Controls, and Hitachi Energy, reflecting the broad attack surface across the ICS ecosystem
Why It Matters
This Patch Tuesday cycle underscores the persistent and escalating vulnerability landscape in industrial control systems, where critical authentication flaws and weak cryptographic practices remain prevalent across major vendors. For AI practitioners and security professionals, these advisories highlight the importance of robust supply-chain security and the need for automated vulnerability monitoring in OT/ICS environments that increasingly intersect with AI-driven operational systems.
Technical Details
- Schneider Electric: CVE-2026-3869 (CVSS 9.2) is a critical authentication bypass in Modicon M580 and M580 Safety PLC controllers; high-severity issues affect PowerLogic T300 RTU and EcoStruxure IT Data Center Expert; medium-severity defect in SCADAPack x70; four older advisories updated to include patches for Modicon MC80
- Siemens: Four critical vulnerabilities addressed in Reyrolle 7SR5 protection relays, Open Interface Services (OIS), Industrial Edge Management, and SIMOVE Fleetmanager/SIPLANT; high-severity flaws in Desigo CC building automation, Teamcenter PLM, Mendix SAML module, and Element Maps; also patched CVE-2026-31431 (CVSS 7.8), a Linux kernel "Copy Fail" vulnerability enabling root shell access
- Aveva: Two high-severity bugs in Pipeline Integrity Monitor PIMBoards — a hardcoded encryption key enabling decryption of sensitive data and MD5-based password hashing allowing reverse-engineering of admin credentials; medium-severity unsafe deserialization in Enterprise SCADA with potential for remote code execution
- Rockwell Automation: Critical/high-severity flaws in RSLinx Classic and 1756-ENBT Ethernet module; high-severity bugs across FactoryTalk Historian ME, FactoryTalk Activation Manager, Redundancy Module Configuration Tool, ControlFLASH, ArmorStart motor controllers, and CompactLogix 5380/5480/5580, GuardLogix 5580, and Compact GuardLogix 5380 controllers
- CISA: Coordinated advisories covering 20+ ICS/OT vendors including Inductive Automation (Ignition), OPC Foundation, Johnson Controls, Hitachi Energy, and others, demonstrating cross-vendor vulnerability coordination
Industry Insight
- The recurrence of fundamental cryptographic failures (hardcoded keys, MD5 hashing) across multiple vendors indicates a systemic gap in secure-by-design practices for ICS products; organizations should prioritize vendors with stronger security development lifecycle commitments
- The convergence of Linux kernel vulnerabilities (CVE-2026-31431) into ICS-adjacent products highlights the expanding attack surface as OT systems increasingly run on commodity OS foundations, necessitating unified patch management across IT and OT domains
- The breadth of CISA's vendor coverage (20+ organizations) suggests coordinated threat intelligence sharing is maturing; AI-driven vulnerability management platforms should integrate CISA advisories as a primary signal source for OT asset risk scoring
Disclaimer: The above content is generated by AI and is for reference only.