Rockwell Automation, Siemens, and Schneider Electric issued July industrial security advisories covering dozens of OT vulnerabilities, with Rockwell disclosing multiple high-impact flaws in control and I/O products. The most severe Rockwell issue, CVE-2026-10577, affects 1715 Redundant IO and exposes a network-accessible debug port without authentication, allowing remote attackers to run intrusive CLI commands, read or delete files, stop tasks, modify memory, and change I/O states; the flaw carries a CVSS v4.0 score of 10.0. Rockwell also reported CVE-2026-9636, a CIP Security certificate revocation handling weakness in several CompactLogix 5380, ControlLogix 5580, GuardLogix 5580, and 1756-EN4 devices that could let a network attacker connect with a certificate that should no longer be trusted, and CVE-2025-11698, a buffer overflow in Logix controller recovery images that can trigger a major non-recoverable fault and cause denial of service.
Separately, CERT VDE published VDE-2026-031 for CVE-2026-4769, a critical WAGO System I/O Field vulnerability caused by an undocumented internal diagnostic function exposed without authentication during early boot. An unauthenticated remote attacker can exploit the startup window to access internal system processes and fully compromise affected 0765-series devices; the issue is rated CVSS 3.1 9.8 and CVSS 4.0 9.3. Siemens also disclosed CVE-2025-40945, an untrusted search path flaw in the IAM Client SDK used across products including COMOS, Designcenter NX, Simcenter, Solid Edge, Teamcenter Visualization, and Tecnomatix, enabling local privilege escalation for authenticated users and reinforcing the breadth of current patching demands across industrial environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
SecurityWeek reported that Siemens, Schneider Electric, and Rockwell Automation released July 2026 Patch Tuesday advisories covering dozens of ICS and OT vulnerabilities. The report highlights nine Siemens advisories, two Schneider advisories, and 12 Rockwell advisories, including critical flaws in Opencenter X and 1715 Redundant IO.
Rockwell Automation disclosed CVE-2025-11698, a buffer overflow affecting 5380/5480/5580 controller recovery image boot firmware before version 1.072. The flaw could let a malicious user write invalid file data and force a controller into a major non-recoverable fault.
Rockwell Automation disclosed CVE-2026-10577, a critical access control vulnerability in 1715 Redundant IO that exposes a network-accessible debug port without proper privilege controls. An unauthenticated remote attacker could use intrusive CLI commands to alter files, memory, tasks, and I/O states.
Siemens disclosed CVE-2025-40945, an untrusted search path flaw in the IAM Client SDK affecting multiple engineering and industrial software products. The issue may allow a locally authenticated user to escalate privileges, and Siemens identified fixed versions and recommended updates.
The CVE record for CVE-2026-9636 was updated to describe improper certificate revocation handling in several Rockwell Automation Logix and 1756-EN4 devices. The issue could allow a network attacker to connect using a certificate that should no longer be trusted.
CERT VDE published advisory VDE-2026-031 for CVE-2026-4769, a critical unauthenticated access vulnerability affecting certain WAGO System I/O Field devices during early boot. The flaw can expose an internal diagnostic interface and enable full system compromise.
Rockwell Automation published a security advisories reference page covering product security notices for its portfolio. The provided reference anchors the page publication date but does not enumerate a specific advisory event on that date.
ABB's advisory index documents cybersecurity alerts and notifications spanning 2012 through 2024 for ABB and B&R industrial products, including vulnerability disclosures and ecosystem-wide threat notices. The reference describes this as an archived advisory collection rather than a single incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcerockwellautomation.com
Open sourceabb.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.