Four Major ICS Vendors Release Security Patches
Schneider Electric and Siemens each patched critical vulnerabilities in industrial control system (ICS) products this week, according to SecurityWeek's September 2026 ICS Patch Tuesday roundup, published September 9, 2026. AVEVA and Rockwell Automation also issued patches for vulnerabilities affecting their industrial automation products during the same cycle.
ICS Patch Tuesday is the informal name for the monthly cadence, aligned with Microsoft's own Patch Tuesday, on which major operational technology (OT) vendors and the Cybersecurity and Infrastructure Security Agency (CISA) coordinate the release of vulnerability advisories for industrial control system products used in manufacturing, energy, water treatment, and building automation. The reporting available for this roundup names the four affected vendors but does not specify individual CVE identifiers, CVSS severity scores, or exact affected product models, so readers who operate this equipment should confirm details directly against each vendor's own advisory before assuming which systems are exposed.
Schneider Electric and Siemens are among the world's largest suppliers of programmable logic controllers (PLCs), SCADA software, and industrial networking hardware, which means fixes from either company routinely affect equipment well beyond factory floors, including water utility controls, power distribution gear, and building management systems. AVEVA supplies industrial software such as SCADA and manufacturing execution systems, while Rockwell Automation is a leading North American industrial automation and PLC vendor.
Why This Matters Even If You Don't Run a Factory
Organizations that don't think of themselves as industrial operators can still run affected equipment. Schneider Electric and Siemens automation components are commonly embedded in HVAC systems, elevator controls, and building access control panels used by hospitals, medical and dental practices, and commercial office buildings, not just plants and utilities. A patch labeled critical for a PLC line can quietly apply to the building management system a facilities contractor installed years ago.
CISA publishes corresponding technical advisories for ICS vulnerabilities, including CVE numbers, affected versions, and mitigation guidance, on its ICS Advisories page. That page, along with each vendor's own product security bulletin, such as Schneider Electric's CERT@VU advisories and Siemens ProductCERT, is the authoritative place to confirm whether a specific model or firmware version is affected before taking action.
OT patching is harder than routine IT patching for structural reasons: many ICS devices control physical processes that can't tolerate unplanned downtime, patches often require vendor-specific validation before deployment, and legacy controllers on plant floors can run for a decade or more without a reboot window. That lag is exactly why unpatched ICS vulnerabilities remain attractive targets long after a fix ships.
Key Takeaway
Don't assume "critical" severity from a vendor advisory applies uniformly to your deployment, and don't assume ICS exposure only affects factories and utilities. Check CISA's ICS Advisories page and each vendor's direct bulletin for the specific product and firmware version you run, then test patches in an offline or staging environment before applying them to production controllers.
What This Means For Your Business
Healthcare practices and clinics: If a facilities contractor manages your HVAC, badge access, or elevator systems, ask whether any Schneider Electric or Siemens building automation components are in use and whether they're covered by this month's patches. This is an operational and access-control question, not just an IT one.
Small businesses and general operators: Take inventory of any networked building or manufacturing equipment on your premises, even if it feels unrelated to your core business. ICS and OT devices are frequently overlooked in asset inventories because they're managed by facilities or maintenance staff rather than IT.
IT and security teams supporting OT environments: Subscribe directly to CISA's ICS advisories and the relevant vendor PSIRT feeds rather than relying on general news coverage for technical details like affected firmware versions. Verify that ICS devices and remote access interfaces are not directly reachable from the public internet, a recurring issue researchers continue to flag in internet-wide scans. Apply vendor-tested patches on a schedule that respects uptime constraints, and back up PLC and controller configurations before any firmware update.
Everyone managing OT or IoT-adjacent systems: Network segmentation between business IT networks and operational technology networks remains one of the most effective compensating controls when a patch can't be applied immediately. If segmentation isn't in place, treat this month's advisories as a prompt to evaluate it, independent of whether your specific equipment turns out to be affected.
People also look for
Keep exploring Security basics
Start with the fundamentals, understand the most likely risks, and choose the next improvement without getting lost in jargon.
- Common question: cybersecurity basicsBuild better cyber hygieneCover the everyday habits and controls that prevent a large share of common incidents.
- Common question: why do hackers target small businessesUnderstand why smaller organizations get targetedSee how opportunity, automation, access, and recovery pressure shape attacker decisions.
- Common question: small business cyber risk assessmentStart with a cyber risk assessmentIdentify important assets, likely threats, current safeguards, and the most useful next steps.
- Common question: cybersecurity solutions for small businessCompare business security optionsFind the right starting point by audience, threat, or compliance need.
- Common question: how hackers choose targetsLearn how attackers choose targetsUnderstand what makes an organization or person visible and attractive to automated attacks.
Learn first. Decide when you are ready.
Keep learning, or apply this to your situation
Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.


