Vulnerability
Published 2026-09-09
Verified 2026-09-19

ICS Patch Tuesday: Schneider Modicon M580 auth flaw CVE-2026-3869 (CVSS 9.2); Siemens critical set

SecurityWeek (9 September 2026) reports Schneider Electric, Siemens, AVEVA, and Rockwell September ICS Patch Tuesday advisories. Schneider published four new advisories and updated four older ones: most severe new issue is critical authentication vulnerability CVE-2026-3869 (CVSS 9.2) in Modicon M580 and Modicon M580 Safety controllers; also high-severity fixes in PowerLogic T300 / Easergy T300 RTU and EcoStruxure IT Data Center Expert, and a medium issue in SCADAPack x70; MC80 patches added to older advisories. Siemens issued nine new advisories (seven on 8 Sep) including critical issues in Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, and SIMOVE Fleetmanager/SIPLANT, plus Copy Fail Linux kernel CVE-2026-31431 (CVSS 7.8) updates. AVEVA PIMBoards/Enterprise SCADA and Rockwell RSLinx/FactoryTalk/CompactLogix advisories also in the same window. Schneider Electric's notifications index returned HTTP 403 from this desk pass — wire URL is primary until the SEVD pages are reachable. OT/ICS operators should pull vendor bulletins and patch by asset criticality.

Product
Schneider Modicon M580/M580 Safety, PowerLogic T300, EcoStruxure IT DCE, SCADAPack x70; Siemens Reyrolle 7SR5, OIS, IEM, SIMOVE/SIPLANT; AVEVA PIMBoards; Rockwell RSLinx/FactoryTalk family
Versions
See vendor September 2026 ICS advisories; Schneider CVE-2026-3869 on Modicon M580 / M580 Safety
CVSS
CVE-2026-3869 9.2 (SecurityWeek citing Schneider); Siemens CVE-2026-31431 7.8
Exploited in Australia?
unknown
Patch to
Apply Schneider/Siemens/AVEVA/Rockwell September 2026 ICS security updates per product bulletin

Primary: SecurityWeek — ICS Patch Tuesday (9 Sep 2026) · Vendor: Schneider Electric security notifications (index) · CVE: CVE-2026-3869, CVE-2026-31431 · Siemens CERT security advisories index

vulnerabilities ot ics network