August 2026 ICS Patch Tuesday: Siemens, Schneider Electric and Phoenix Contact Fix Serious Flaws in Factory Equipment
A batch of August security updates covers industrial control systems that run factories, power networks and buildings. One Siemens flaw scores the maximum possible severity rating and lets attackers run any code they like on a connected device without needing a password.

Key points
- Siemens published 10 security advisories in August 2026, including one rated maximum severity for its Simatic IoT2050 Advanced device.
- The worst Siemens flaw lets a remote attacker run any code on the device without a username or password.
- Schneider Electric patched two products: NetBotz 5 (remote code execution) and PowerChute Serial Shutdown (brute-force login weakness).
- Phoenix Contact fixed multiple flaws in PLCnext firmware, including one that lets attackers run malicious database commands without logging in.
- The US Cybersecurity and Infrastructure Security Agency (CISA) published three additional advisories covering Pulsetto, Mira, and Johnson Controls products.
Siemens, Schneider Electric and Phoenix Contact all dropped security updates this week for the industrial computers and controllers that keep factories, power grids and large buildings running. Think of these devices the way you would think of the nervous system of a manufacturing plant: if someone takes control of them, the whole operation can stop, or worse, behave dangerously.
What is the worst flaw, and who is at risk?
The most serious issue sits inside the Siemens Simatic IoT2050 Advanced, a small industrial computer used to connect factory equipment to corporate networks. The flaw is a missing-authentication vulnerability, meaning the device accepts commands from strangers on the internet without asking for a username or password.
An attacker who finds one of these devices online could send it instructions and run any code they choose, with full administrative control. That is as bad as it sounds. Siemens has not indicated active exploitation in the wild, its term for attacks already happening against real customers, but the maximum severity rating (a perfect 10 on the CVSS scale, the standard 0-to-10 scoring system security researchers use to rank how dangerous a flaw is) means patching should not wait.
Siemens also fixed a critical code-execution flaw in Siveillance Video Management Servers, software used to manage security cameras in large facilities.
| Vendor | Product | Severity | What an attacker could do |
|---|---|---|---|
| Siemens | Simatic IoT2050 Advanced | Maximum (10.0) | Run any code without a password |
| Siemens | Siveillance Video Management Server | Critical | Execute malicious code remotely |
| Siemens | Solid Edge, Simcenter Nastran, others | High | Crash software, steal files, gain admin rights |
| Schneider Electric | NetBotz 5 | High | Execute commands on the device |
| Schneider Electric | PowerChute Serial Shutdown | Medium | Repeatedly guess passwords; disrupt service |
| Phoenix Contact | PLCnext firmware | High | Crash the device or run malicious database queries |
Should building or factory managers be worried?
Yes, if any of these products are in your network and have not been updated. The practical risk for most people is indirect: disruption to a factory could delay products, a compromised building-management system could affect heating or access control.
If you manage facilities that use any of the named products, forward this article to your IT or operational technology team today. They will know whether your site runs these devices.
CISA, the US government's cybersecurity agency, published three separate advisories on the same day covering flaws in Pulsetto, Mira (made by Quanovate Tech) and Johnson Controls equipment, all of which touch building and industrial systems.
Phoenix Contact's PLCnext firmware update is worth flagging to engineers: among the fixed flaws is a SQL-injection weakness, where an attacker feeds a device specially crafted text that tricks its database into running unintended commands. SQL injection is a technique as old as the early web; finding it in factory firmware in 2026 is a reminder that classic attack methods never really retire.
Common questions
Do these flaws affect home users?
Almost certainly not. These are specialist industrial and commercial devices, not consumer products. Homes do not run Simatic IoT2050 units or PLCnext controllers.
How can organisations protect themselves right now?
Apply the vendor patches immediately, restrict internet access to industrial control devices wherever possible, and make sure staff who manage these systems know how to spot unusual device behaviour and report it quickly.



