August 2026 ICS Patch Tuesday: Siemens, Schneider Electric and Phoenix Contact Fix Serious Flaws in Factory Equipment

A batch of August security updates covers industrial control systems that run factories, power networks and buildings. One Siemens flaw scores the maximum possible severity rating and lets attackers run any code they like on a connected device without needing a password.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
An industrial factory floor with manufacturing equipment and control systems visible, computer workstations running factory management software in the foregroun
Share

Key points

  • Siemens published 10 security advisories in August 2026, including one rated maximum severity for its Simatic IoT2050 Advanced device.
  • The worst Siemens flaw lets a remote attacker run any code on the device without a username or password.
  • Schneider Electric patched two products: NetBotz 5 (remote code execution) and PowerChute Serial Shutdown (brute-force login weakness).
  • Phoenix Contact fixed multiple flaws in PLCnext firmware, including one that lets attackers run malicious database commands without logging in.
  • CISA published three additional advisories covering Pulsetto, Mira by Quanovate Tech, and Johnson Controls products.

Siemens, Schneider Electric and Phoenix Contact dropped security updates this week for the industrial computers and controllers that keep factories, power grids and large buildings running. Think of these devices as the nervous system of a manufacturing plant: if someone takes control of them, the whole operation can stop, or behave dangerously.

What is the worst flaw, and who is at risk?

The most serious issue is inside the Siemens Simatic IoT2050 Advanced, a small industrial computer used to connect factory equipment to corporate networks. It's a missing-authentication vulnerability, meaning the device accepts commands from strangers on the internet without asking for credentials.

An attacker who finds one of these devices online could send instructions and run any code they choose, with full administrative control. Siemens hasn't indicated active exploitation in the wild, but the maximum CVSS score of 10.0 (the standard 0-to-10 scale researchers use to rank how dangerous a flaw is) means patching shouldn't wait. We covered Siemens' firmware debt in detail on 28 July when the company flagged more than 300 unpatched Linux CVEs in its S7-1500 MFP controllers; today's advisory is a separate product but the same pattern of slow-moving industrial patching.

Siemens also fixed a critical code-execution flaw in Siveillance Video Management Servers, software used to manage security cameras in large facilities.

Vendor Product Severity What an attacker could do
Siemens Simatic IoT2050 Advanced Maximum (10.0) Run any code without a password
Siemens Siveillance Video Management Server Critical Execute malicious code remotely
Siemens Solid Edge, Simcenter Nastran, others High Crash software, steal files, gain admin rights
Schneider Electric NetBotz 5 High Execute commands on the device
Schneider Electric PowerChute Serial Shutdown Medium Repeatedly guess passwords; disrupt service
Phoenix Contact PLCnext firmware High Crash the device or run malicious database queries

Should building or factory managers be worried?

Yes, if any of these products are in your network and haven't been updated. The practical risk for most organisations is indirect: a compromised building-management system could affect heating or access control, and factory disruption delays product.

If you manage facilities running any of the named products, get this in front of your IT or operational technology team. CISA, the US government's cybersecurity agency, published its three advisories on the same day covering Pulsetto, Mira and Johnson Controls equipment, all touching building and industrial systems.

Phoenix Contact's PLCnext update deserves a flag for engineers: one of the fixed flaws is a SQL-injection weakness, where an attacker feeds specially crafted text that tricks a device's database into running unintended commands. SQL injection is a technique as old as the early web. Spotting it in factory firmware in 2026 is a reminder that classic attack methods don't retire; they migrate.

Common questions

Do these flaws affect home users?

Almost certainly not. These are specialist industrial and commercial devices. Homes don't run Simatic IoT2050 units or PLCnext controllers.

How can organisations protect themselves right now?

Apply the vendor patches immediately, restrict internet access to industrial control devices wherever possible, and make sure staff who manage these systems know how to spot unusual device behaviour and report it.

© 2026 Threat Vectr