Schneider Electric, Siemens, and Aveva patch critical flaws in industrial control systems
September 2026's industrial Patch Tuesday brings fixes for authentication failures, hardcoded encryption keys, and a Linux kernel flaw that lets attackers gain full system control.

Key points
- Schneider Electric's Modicon M580 controller carries a critical authentication flaw rated 9.2 out of 10 on the severity scale, tracked as CVE-2026-3869.
- Siemens patched a Linux kernel vulnerability, CVE-2026-31431, that allows an attacker to gain root access, meaning full administrative control, across several of its products.
- Aveva's Pipeline Integrity Monitor stored passwords using MD5, a hashing method so weak that attackers can often reverse it back into the original password.
- Rockwell Automation separately published nine advisories covering critical and high-severity bugs in products including RSLinx Classic and CompactLogix controllers.
- The US Cybersecurity and Infrastructure Security Agency (CISA) has published advisories for more than twenty additional industrial products since the last round of patches in August.
Every second Tuesday of the month, major industrial technology companies release security patches, fixes that close gaps criminals could use to interfere with factory equipment, power systems, and critical infrastructure. September 2026 is a heavy one.
What did Schneider Electric fix?
The most urgent fix is a critical authentication flaw in the Modicon M580 and Modicon M580 Safety controllers, rated 9.2 out of 10 in severity. Authentication controls who is allowed to send commands to a system; a flaw here means an unauthorised person could potentially take control of the controller without needing a valid password.
Schneider Electric published four new advisories and updated four older ones, including one originally issued in 2019, to note that patches are now also available for the Modicon MC80 controller. The company also patched high-severity bugs in its PowerLogic T300 platform and EcoStruxure IT Data Center Expert product, and a medium-severity issue in SCADAPack x70 devices.
What did Siemens and Aveva fix?
Siemens published nine new advisories. Four cover critical-severity vulnerabilities across Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT products. High-severity fixes followed for Desigo CC, Teamcenter, the Mendix SAML module (a single sign-on component that handles user logins), and Element Maps.
Siemens also pushed updates to close CVE-2026-31431, a Linux kernel flaw disclosed in April that allows an attacker who already has limited access to escalate to a root shell, meaning they gain unrestricted control over the operating system.
| Vendor | Product | Flaw | Severity (CVSS) |
|---|---|---|---|
| Schneider Electric | Modicon M580 / M580 Safety | Authentication bypass, CVE-2026-3869 | 9.2 (Critical) |
| Siemens | Multiple products | Linux kernel root access, CVE-2026-31431 | 7.8 (High) |
| Siemens | Reyrolle 7SR5, OIS, others | Various critical flaws | Critical |
| Aveva | Pipeline Integrity Monitor | Hardcoded key, weak MD5 password hashing | High |
| Aveva | Enterprise SCADA | Unsafe deserialization (remote code execution risk) | Medium |
Aveva's problems centre on its PIMBoards component inside Pipeline Integrity Monitor. One flaw uses a hardcoded encryption key, meaning the key is baked into the software itself and is the same for every installation, so anyone who finds it can decrypt sensitive data. A second issue involves passwords stored using MD5, an outdated algorithm that makes it relatively straightforward for an attacker to work backwards from the stored value to the original password. A third advisory, published before this Patch Tuesday, warns of an unsafe deserialization bug in Enterprise SCADA, where data fed into the system can be crafted to execute malicious code remotely.
What should organisations running this equipment do?
Apply the patches. Industrial control systems often run for years without updates, and that reluctance is exactly what attackers count on. Operators should check vendor portals directly for the relevant advisories and follow any temporary mitigations if a full patch cannot be applied immediately.
CISA, which is the US government agency responsible for critical infrastructure security, has jurisdiction over many of these products in the United States and has issued its own advisories covering more than twenty additional vendors since August's patch cycle, including Johnson Controls, Hitachi Energy, and Furuno. Organisations outside the US should check with their relevant national regulator.
First reported by SecurityWeek, the breadth of this month's advisories is a reminder that industrial equipment connected to a network carries real security obligations, not just operational ones.



