HomeUpdatesICS Patch Tuesday: Vulnerability fixes from Siemens, Schneider Electric

ICS Patch Tuesday: Vulnerability fixes from Siemens, Schneider Electric

Major security updates have been released for the industrial control systems (ICS), with leading manufacturers such as Siemens, Schneider Electric, Mitsubishi Electric and Moxa announcing new fixes for vulnerabilities identified in their critical products.

ICS Patch Tuesday security vulnerabilities of industrial systems

These updates concern devices and platforms widely used in industrial facilities, energy networks, data centers and automation systems, which makes their rapid installation particularly important to avoid cyberattacks.

Schneider Electric updates on critical automation systems

Schneider Electric has released six new security advisories, each addressing a specific vulnerability. Some of them are rated as high severity and impact key infrastructure management solutions.

See also: ICS Patch Tuesday: Addresses Schneider Electric and Siemens vulnerabilities

Among the most significant issues is a hardcoded credentials vulnerability in the EcoStruxure IT Data Center Expert system , which could allow unauthorized access to critical data center management environments.

Additionally, bugs were identified that allow local code execution in the EcoStruxure Power Monitoring Expert and Power Operation platforms , while an issue was recorded in EcoStruxure Automation Expert that could lead to command execution and a complete system compromise .

The company also patched medium-severity vulnerabilities in Modicon controllers, which include DoS and the possibility of account takeover via XSS. It also addressed a remote code execution vulnerability in EcoStruxure Foxboro DCS.

Security interventions in Siemens industrial systems

Siemens also announced six new security updates covering a range of industrial products and development tools. Among the most serious issues is a critical stored XSS vulnerability affecting Simatic S7-1500 devices , which are widely used in industrial automation networks .

Additionally, the company warned of a potential misconfiguration in Mendix applications, which could create exploitable conditions for malicious users.

The updates also include issues arising from third-party dependencies, such as libraries or platforms widely used in the industry. Among these are vulnerabilities related to Fortinet and OpenSSL.

See also: ICS Patch Tuesday: Vulnerabilities fixed by Siemens, Schneider, Aveva, Phoenix Contact

At the same time, high and medium severity issues were fixed in the Sicam Siapp SDK, while a low severity issue affecting Heliox EV.

ICS Patch Tuesday: Vulnerability fixes from Siemens, Schneider Electric

Vulnerabilities in Mitsubishi Electric CNC systems

Mitsubishi Electric has issued a new advisory regarding a DoS in Numerical Control. The vulnerability can be exploited remotely and affects several product lines, including the C80, M800, M800V and M700V.

Earlier this month, the company had already warned of additional DoS issues in MELSEC iQ-F Series controllers, highlighting the need to regularly update industrial systems.

Advisory updates also from Moxa

Moxa has published four new security advisories. Three of them address vulnerabilities discovered in Intel used in the company's devices.

The fourth announcement informs customers that Moxa products are not affected by a recent vulnerability in the GNU Inetutils networking tool , thus reassuring system administrators who use the equipment.

New ICS warnings from CISA

At the same time, the US Cybersecurity and Infrastructure Security Agency published new advisories for vulnerabilities in various industrial and network infrastructure devices.

See also: Critical vulnerabilities in Siemens and Schneider Electric products

The affected systems include Ceragon Siklu MultiHaul and EtherHaul network cameras , as well as Lantronix EDS3000PS and EDS5000 devices. Security issues have also been reported in Apeman products.

Microsoft Patch Tuesday March 2026 security updates

The agency has issued another warning about a vulnerability in Honeywell building controllers. According to the information, there was a disagreement between the vendor and the researcher who discovered the problem about how serious the actual impact is.

The importance of security in industrial networks

The latest revelations highlight the ever-increasing importance of systems industrial automation. ICS form the backbone of critical infrastructure, from manufacturing plants to energy grids and transportation.

As more and more industrial platforms connect to corporate networks or the internet, the attack surface also increases. For this reason, organizations and businesses are called upon to implement policies of regular software updates, network segregation and continuous threat monitoring.

Prompt installation of fixes announced by manufacturers is considered critical to maintaining security in industrial environments where even a minor outage can have significant financial or operational consequences.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS