Schneider Electric and Siemens released September 2026 security advisories for critical vulnerabilities in industrial control products used to run plants, utilities, and other operations. Schneider’s most severe issue is CVE-2026-3869, a CVSS 9.2 authentication flaw in Modicon M580 and M580 Safety controllers. Siemens disclosed critical flaws in Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT, and said updates are rolling out for the Copy Fail Linux kernel root-shell bug CVE-2026-31431. The roundup also notes AVEVA and Rockwell patches for additional ICS products.
Why it matters: These products sit in operational technology environments, so unpatched flaws can put real-world industrial processes and facility operations at risk. Operators should review vendor advisories quickly, identify exposed products, and prioritize patching or mitigations for internet-reachable and safety-relevant systems.
Ionut Arghire
2026.09.09
100% relevant
This article establishes a distinct September 2026 ICS patch cycle story centered on new critical vendor advisories and the specific affected industrial products.
← Back to all stories