Siemens, Schneider Electric, and Phoenix Contact released August 2026 security advisories for industrial control and operational technology products used in factories, buildings, and infrastructure. Siemens disclosed 10 advisories, including a maximum-severity missing-authentication flaw in Simatic IoT2050 Advanced devices that can let a remote unauthenticated attacker run code with elevated privileges, and a critical code-execution issue in Siveillance Video Management Servers. Schneider patched vulnerabilities in NetBotz 5 and PowerChute Serial Shutdown, and Phoenix Contact fixed multiple PLCnext firmware flaws that can enable denial of service, unexpected behavior, or malicious SQL queries.
Why it matters: These products are used to monitor and control real-world operations, so flaws can affect safety, uptime, and physical processes. Organizations using the affected Siemens, Schneider Electric, or Phoenix Contact systems should review the August advisories and apply updates or mitigations promptly, especially for internet-reachable devices.
Eduard Kovacs
2026.08.12
100% relevant
This article establishes a distinct August 2026 ICS patch cycle story centered on newly published vendor advisories and specific vulnerabilities across Siemens, Schneider Electric, and Phoenix Contact products.
← Back to all stories