Schneider Electric, Siemens and AVEVA Patch Critical Industrial Control System Flaws in September Patch Cycle

Industrial automation vendors Schneider Electric, Siemens and AVEVA published their September 2026 Patch Tuesday advisories, disclosing and fixing a batch of vulnerabilities across products used to run and monitor industrial and critical infrastructure operations.

A Critical Flaw in Widely Deployed Safety Controllers

The most severe issue disclosed, tracked as CVE-2026-3869 with a CVSS score of 9.2, is a critical authentication vulnerability affecting Schneider Electric’s Modicon M580 and Modicon M580 Safety programmable controllers, hardware widely used to control physical processes in manufacturing and critical infrastructure environments. Schneider Electric published four new security advisories and updated four others, including one originally issued in 2019, and separately resolved high-severity flaws in its PowerLogic T300 platform (formerly Easergy T300) and EcoStruxure IT Data Center Expert product, along with a medium-severity issue in its SCADAPack x70 line.

Denial-of-Service Risk in Rockwell’s Historian Software

Rockwell Automation separately disclosed CVE-2026-12661, a high-severity denial-of-service vulnerability in FactoryTalk Historian Machine Edition, in which a network-adjacent, authenticated attacker can send crafted requests to the web interface to trigger a buffer overflow that crashes the device. AVEVA’s FactoryTalk Historian SE product, which is built on the AVEVA PI Server, carries a related issue that lets an unauthenticated attacker remotely crash or exhaust memory on the PI Message Subsystem, requiring a power cycle to recover affected systems.

Part of a Broader Monthly Cadence Across the Sector

Since the previous month’s patch cycle, CISA has separately published advisories covering additional industrial and IoT vulnerabilities from vendors including Inductive Automation, Hitachi Energy, Furuno, Johnson Controls and others, underscoring how large and continuous the flow of disclosed operational technology vulnerabilities has become. None of the newly disclosed Schneider, Siemens, AVEVA or Rockwell flaws in this cycle have been reported as under active exploitation, but organizations running the affected controllers and historian software are advised to apply vendor patches and review network segmentation between control systems and general IT networks.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *