Schneider Electric, Siemens, Aveva, and Rockwell Automation released security advisories and patches for industrial control system and operational technology products. Schneider Electric fixed CVE-2026-3869, a CVSS 9.2 authentication vulnerability affecting Modicon M580 and M580 Safety controllers that could permit unauthorized access and complete compromise of affected systems.
Siemens issued nine advisories, four covering critical vulnerabilities, and began deploying fixes for the Linux kernel Copy Fail flaw, CVE-2026-31431, which can provide root-shell access. Aveva remediated sensitive-data exposure and password-security issues in Pipeline Integrity Monitor, while Rockwell Automation published nine advisories affecting RSLinx Classic, industrial controllers, and FactoryTalk products; organizations should prioritize applying vendor patches to exposed OT assets.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Siemens issued seven of its nine new security advisories on September 8, including advisories for critical vulnerabilities affecting products such as Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, SIMOVE Fleetmanager, and SIPLANT.
Aveva issued an advisory for four PIMBoards component vulnerabilities in Pipeline Integrity Monitor. Two were high severity, including a hardcoded encryption key that could expose sensitive information and MD5-hashed passwords that could enable recovery of administrative passwords.
Siemens published nine new and updated nine existing industrial-product advisories during the September 2026 Patch Tuesday cycle. It also announced product updates for Linux kernel Copy Fail vulnerability CVE-2026-31431, which has a CVSS score of 7.8 and can enable root shell access.
During September 2026 ICS Patch Tuesday, Schneider Electric issued four new and updated four existing advisories. The updates addressed CVE-2026-3869, a CVSS 9.2 authentication vulnerability affecting Modicon M580 and M580 Safety controllers, as well as flaws in PowerLogic T300, EcoStruxure IT Data Center Expert, SCADAPack x70, and Modicon MC80 products.
CISA published vulnerability advisories since the prior Patch Tuesday for products from numerous vendors, including CareCam, Tycon Systems, Inductive Automation, Johnson Controls, Hitachi Energy, Haiwell, and others.
Rockwell Automation published nine advisories covering critical and high-severity flaws in RSLinx Classic, industrial controllers, and FactoryTalk products, including CompactLogix and GuardLogix controller families.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcemalware.news
Open sourcesecurityweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.