Skip to content
Bellator Cyber Guard
News7 min readStandard

September ICS Patch Tuesday Fixes Critical Flaws

Schneider Electric, Siemens, AVEVA, and Rockwell Automation patched ICS vulnerabilities in September 2026. Here's what OT operators should do now.

By Bellator Cyber Guard Security Team

Four Major ICS Vendors Release Security Patches

Schneider Electric and Siemens each patched critical vulnerabilities in industrial control system (ICS) products this week, according to SecurityWeek's September 2026 ICS Patch Tuesday roundup, published September 9, 2026. AVEVA and Rockwell Automation also issued patches for vulnerabilities affecting their industrial automation products during the same cycle.

ICS Patch Tuesday is the informal name for the monthly cadence, aligned with Microsoft's own Patch Tuesday, on which major operational technology (OT) vendors and the Cybersecurity and Infrastructure Security Agency (CISA) coordinate the release of vulnerability advisories for industrial control system products used in manufacturing, energy, water treatment, and building automation. The reporting available for this roundup names the four affected vendors but does not specify individual CVE identifiers, CVSS severity scores, or exact affected product models, so readers who operate this equipment should confirm details directly against each vendor's own advisory before assuming which systems are exposed.

Schneider Electric and Siemens are among the world's largest suppliers of programmable logic controllers (PLCs), SCADA software, and industrial networking hardware, which means fixes from either company routinely affect equipment well beyond factory floors, including water utility controls, power distribution gear, and building management systems. AVEVA supplies industrial software such as SCADA and manufacturing execution systems, while Rockwell Automation is a leading North American industrial automation and PLC vendor.

Why This Matters Even If You Don't Run a Factory

Organizations that don't think of themselves as industrial operators can still run affected equipment. Schneider Electric and Siemens automation components are commonly embedded in HVAC systems, elevator controls, and building access control panels used by hospitals, medical and dental practices, and commercial office buildings, not just plants and utilities. A patch labeled critical for a PLC line can quietly apply to the building management system a facilities contractor installed years ago.

CISA publishes corresponding technical advisories for ICS vulnerabilities, including CVE numbers, affected versions, and mitigation guidance, on its ICS Advisories page. That page, along with each vendor's own product security bulletin, such as Schneider Electric's CERT@VU advisories and Siemens ProductCERT, is the authoritative place to confirm whether a specific model or firmware version is affected before taking action.

OT patching is harder than routine IT patching for structural reasons: many ICS devices control physical processes that can't tolerate unplanned downtime, patches often require vendor-specific validation before deployment, and legacy controllers on plant floors can run for a decade or more without a reboot window. That lag is exactly why unpatched ICS vulnerabilities remain attractive targets long after a fix ships.

Key Takeaway

Don't assume "critical" severity from a vendor advisory applies uniformly to your deployment, and don't assume ICS exposure only affects factories and utilities. Check CISA's ICS Advisories page and each vendor's direct bulletin for the specific product and firmware version you run, then test patches in an offline or staging environment before applying them to production controllers.

What This Means For Your Business

Healthcare practices and clinics: If a facilities contractor manages your HVAC, badge access, or elevator systems, ask whether any Schneider Electric or Siemens building automation components are in use and whether they're covered by this month's patches. This is an operational and access-control question, not just an IT one.

Small businesses and general operators: Take inventory of any networked building or manufacturing equipment on your premises, even if it feels unrelated to your core business. ICS and OT devices are frequently overlooked in asset inventories because they're managed by facilities or maintenance staff rather than IT.

IT and security teams supporting OT environments: Subscribe directly to CISA's ICS advisories and the relevant vendor PSIRT feeds rather than relying on general news coverage for technical details like affected firmware versions. Verify that ICS devices and remote access interfaces are not directly reachable from the public internet, a recurring issue researchers continue to flag in internet-wide scans. Apply vendor-tested patches on a schedule that respects uptime constraints, and back up PLC and controller configurations before any firmware update.

Everyone managing OT or IoT-adjacent systems: Network segmentation between business IT networks and operational technology networks remains one of the most effective compensating controls when a patch can't be applied immediately. If segmentation isn't in place, treat this month's advisories as a prompt to evaluate it, independent of whether your specific equipment turns out to be affected.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

People also look for

Keep exploring Security basics

Start with the fundamentals, understand the most likely risks, and choose the next improvement without getting lost in jargon.

Learn first. Decide when you are ready.

Keep learning, or apply this to your situation

Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.