ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical PLC Flaws

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical PLC Flaws

The industrial automation sector is locked in a quiet arms race. Each Patch Tuesday now functions as a public status report on the security posture of the world's programmable logic controllers (PLCs), and the September 2026 ICS Patch Tuesday cycle shows precisely why operators cannot afford to fall behind. Schneider Electric and Siemens led the round by disclosing critical and high-severity vulnerabilities across PLC, SCADA, and engineering platforms, with AVEVA and Rockwell Automation following with their own fixes. For plant engineers and OT security teams, the signal is blunt: unpatched controllers are now a primary attack surface.

Analyst Insight: The convergence of IT and OT has turned Patch Tuesday into a risk-management checkpoint for production environments. Vendors are no longer the only ones tracking these advisories — threat actors are reading them too, and they move quickly once a proof-of-concept appears.

Schneider Electric Expands Its Modicon PLC Patch Portfolio

Schneider Electric published four new security advisories and updated four existing ones on September 9, 2026. One of the updated advisories dates back to 2019, a reminder that even long-running vulnerability records can resurface with expanded scope.

Most notably, the vendor added patches for the Modicon MC80 PLC controller. The flaw involves improper input validation and improper restriction of operations within the bounds of a memory buffer, carrying a CVSS v3.1 base score of 8.1 and a High severity rating.

Schneider Electric September 2026 advisory breakdown

New advisories: 4

Updated advisories: 4 (one originally released in 2019)

Flagship patch target: Modicon MC80 PLC controller

Associated weakness: Improper input validation and memory-buffer restriction (CWE-119)

CVSS v3.1 base score: 8.1 (High)

Market Trend: Legacy Modicon controllers remain deeply embedded in manufacturing, energy, and critical infrastructure. The revival of a 2019 advisory signals that vendor security teams are re-auditing mature product lines — a development OEMs and system integrators should factor into lifecycle and upgrade planning.

Siemens Delivers Nine New Advisories

Siemens published nine new advisories since the previous Patch Tuesday, seven of them landing on September 8. The disclosures span a broad product range and include critical issues such as device takeover, remote code execution, cross-site scripting, arbitrary file access, missing authentication, and session hijacking.

Several flaws affect third-party components, widening the attack surface beyond Siemens' own code. One Siemens product is also impacted by a PAN-OS vulnerability that has been exploited in the wild, underscoring the real-world urgency of this cycle.

Siemens September 2026 vulnerability landscape

New advisories since prior Patch Tuesday: 9

Published on September 8: 7

Critical vulnerability classes: Device takeover, remote code execution, cross-site scripting, arbitrary file access, missing authentication, session hijacking

Third-party component exposure: Yes — several advisories involve third-party libraries

Active exploitation flag: One Siemens product affected by an in-the-wild PAN-OS vulnerability

Analyst Insight: The presence of an in-the-wild exploited vulnerability inside a Siemens-affiliated product elevates this Patch Tuesday from routine hygiene to urgent remediation. OT security teams should prioritize the exploited component ahead of severity score alone — active exploitation trumps theoretical risk.

AVEVA and Rockwell Automation Join the Fix Cycle

AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. Their participation completes a coordinated, multi-vendor remediation wave across the major PLC and automation ecosystem.

The breadth of this cycle — spanning controllers, engineering software, and SCADA platforms — reinforces how deeply software supply chains now run through industrial operations.

ICS Patch Tuesday: What It Means for PLC and OT Security Teams

The September 2026 ICS Patch Tuesday cycle is not a one-off anomaly; it is the new operational baseline. Asset owners running Modicon, Simatic, AVEVA, or Rockwell platforms should triage advisories by exposure, exploitability, and connectivity rather than severity score alone.

Teams should verify firmware and software versions against vendor notifications, segment OT networks from enterprise IT, and treat third-party component flaws as first-class risks. Where patching is delayed, compensating controls such as network isolation and access restriction become essential.

Recommended triage and remediation checklist

1. Inventory affected assets and confirm exact firmware and software versions.

2. Prioritize any vulnerability with confirmed or likely active exploitation.

3. Evaluate third-party component advisories for transitive exposure.

4. Apply vendor patches or documented mitigations in a controlled maintenance window.

5. Segment OT networks and restrict remote access where patching must be deferred.

6. Monitor CISA and vendor ProductCERT channels for updated advisories.

Frequently Asked Questions

What is ICS Patch Tuesday?

ICS Patch Tuesday is the monthly cadence, aligned with the broader security industry's patch cycle, in which major industrial control system vendors such as Schneider Electric, Siemens, AVEVA, and Rockwell Automation publish security advisories for their automation and PLC products. It mirrors Microsoft's Patch Tuesday but focuses on OT and industrial assets.

Why is the Modicon MC80 patch significant?

The Modicon MC80 patch matters because it was added to an advisory originally released in 2019, showing that Schneider Electric is actively re-auditing mature controllers. The underlying weakness — improper input validation and memory-buffer restriction — carries a CVSS v3.1 score of 8.1 and can impact PLCs deployed across critical manufacturing and energy sectors.

Which Siemens vulnerabilities are most urgent?

The most urgent Siemens items include critical classes such as device takeover, remote code execution, and missing authentication. One Siemens product is affected by a PAN-OS vulnerability already exploited in the wild, which should be treated as a top remediation priority regardless of its nominal severity score.

How should plant operators respond before patching?

Operators should isolate affected systems from untrusted networks, restrict remote access, verify inventory and versions, and apply vendor-documented mitigations. Compensating controls are essential when production uptime requirements prevent immediate patching.

Related Articles

Tillbaka till blogg