September ICS Patch Tuesday brings critical fixes from Schneider Electric, Siemens, and Aveva, including CVSS 9.2 authentication flaw CVE-2026-3869 in Modicon M580 controllers.
Schneider Electric's September advisories include a critical authentication vulnerability, CVE-2026-3869 with a CVSS score of 9.2, in Modicon M580 and Modicon M580 Safety controllers, plus high-severity bugs in PowerLogic T300 and EcoStruxure IT Data Center Expert. Siemens published nine new advisories, four rated critical across Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT, and began rolling out fixes for CVE-2026-31431, a 7.8-rated Linux kernel flaw enabling root shell access. Aveva disclosed four flaws in Pipeline Integrity Monitor's PIMBoards, including a hardcoded encryption key and MD5-hashed passwords, plus an unsafe deserialization issue in Enterprise SCADA. Rockwell Automation separately issued nine advisories covering RSLinx Classic and multiple controller products.
Rockwell's 1756-ENBT ControlLogix EtherNet/IP bridge (all versions) is vulnerable to DoS via crafted CIP packets, crashing the module until manual restart.
CISA republished Rockwell Automation's advisory for CVE-2025-10478, a CWE-754 flaw affecting all versions of the 1756-ENBT ControlLogix EtherNet/IP bridge, scored CVSS 7.5. A crafted CIP packet can crash the module, and the device requires a restart to recover. Affected critical infrastructure sectors include critical manufacturing, food and agriculture, transportation systems, and water. No public exploitation has been reported; CISA recommends minimizing network exposure.
CISA advisory for CVE-2026-12663 (CVSS 7.3) in Rockwell Automation ControlFLASH <=V15.07: world-writable install directory enables local code execution.
Rockwell Automation reported CVE-2026-12663 in ControlFLASH V15.07 and earlier, where the installer grants write permissions on the installation directory to the Everyone group. An attacker could plant malicious code there and execute it at the logged-in user's privilege level. The issue is local only and not remotely exploitable; no public exploitation has been reported to CISA.
CISA flags two flaws (CVE-2026-19471, CVE-2026-19472) in Rockwell Automation ArmorStart LT <=v2.001: stored XSS and web server denial-of-service.
Rockwell Automation reported two issues in the embedded web server of ArmorStart LT v2.001 and earlier. CVE-2026-19471 involves multiple stored cross-site scripting flaws (CVSS 7.3) where unsanitized input is stored server-side and executes in other users' browsers. CVE-2026-19472 is a denial-of-service issue (CVSS 7.5) triggered by a crafted HTTP PUT request that exhausts web server resources. No public exploitation has been reported to CISA.
Forescout used Anthropic's Claude to port a working pre-auth RCE exploit for CVE-2021-31886 between WAGO PLCs, executing ARM shellcode on live hardware.
Forescout Vedere Labs used Claude interactively to port an RCE exploit for CVE-2021-31886, a CVSS 9.8 stack buffer overflow in the Nucleus FTP server's USER command, from a WAGO 750-852 to a WAGO 750-831 PLC, running attacker-supplied ARM shellcode. The final RCE stage cost $535.74 in API usage over 8 hours 32 minutes, and a follow-up attempt to build a C2 implant permanently bricked the device. CERT@VDE lists many Nucleus V1-based WAGO models as vulnerable with no updates available; Siemens plans no Nucleus NET remediation. The work follows a joint NSA/CISA/FBI/DOE/EPA advisory warning of AI-generated exploitation scripts targeting internet-exposed Siemens S7 PLCs.
Canada's Cyber Centre flags vulnerabilities across multiple Rockwell Automation ICS products including ControlLogix 5580 and RSLinx Classic.
Canadian Centre for Cyber Security advisory AV26-869, dated September 1, 2026, lists vulnerabilities in Rockwell Automation products: 1756-ENBT Module (all versions), ArmorStart LT (v2.001 and earlier), CompactLogix 5380 / ControlLogix 5580 (V33 and earlier plus several V34-V36 releases), and RSLinx Classic (V4.50 and earlier). It references Rockwell advisories SD1792, SD1794, SD1797, and SD1798 and urges users to apply updates as available.
CISA advisory maps CVE-2021-42260 to Rockwell ControlLogix, CompactLogix, and GuardLogix controllers with firmware below per-series patch levels.
CISA published an ICS advisory associating CVE-2021-42260 with multiple Rockwell Automation controller families: ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, CompactLogix 5480, and Compact GuardLogix 5380. Affected firmware versions fall below 34.015, 35.014, 36.013, and 37.011 depending on the series. The vendor provides updated firmware as remediation.
CISA warns CVE-2025-12768 and CVE-2026-12661 in Rockwell Historian ME could crash devices or allow remote code execution via out-of-bounds writes; CVSS 8.
CISA issued an ICS advisory for Rockwell Automation Historian ME Series B 5.202 and Series C 7.101. CVE-2025-12768 and CVE-2026-12661 involve out-of-bounds write and stack-based buffer overflow flaws that could crash the accessed device or enable remote code execution. The product is deployed across chemical, critical manufacturing, healthcare, and water and wastewater sectors worldwide.
CISA flags four flaws (CVE-2026-9621/9622/9624/9625) in Rockwell RSLinx Classic 4.50 and below that can cause denial-of-service conditions; CVSS 8.6.
CISA published an ICS advisory covering four vulnerabilities in Rockwell Automation RSLinx Classic versions 4.50 and below. The integer overflow, underflow, and classic buffer overflow flaws (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) could let attackers cause denial-of-service conditions. The product is deployed worldwide, primarily in critical manufacturing.
CISA warns Rockwell Automation Logix controllers (ControlLogix, CompactLogix, GuardLogix) up to V36.012 are affected by CVE-2026-9637 (CVSS 7.5).
CISA published ICS advisory ICSA-26-244-03 covering the Rockwell Automation Logix Platform. Affected products include ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 running firmware through V33 and selected V34-V36 releases. The underlying vulnerability is tracked as CVE-2026-9637 with a vendor CVSS v3 score of 7.5. The advisory provides guidance for industrial operators to update affected controllers.
CISA details CVE-2026-16675, a CVSS 7.8 privilege escalation flaw in Rockwell FactoryTalk Activation Manager V5.02 and below, with vendor fixes available.
CISA issued an ICS advisory for Rockwell Automation FactoryTalk Activation Manager. CVE-2026-16675 is a privilege escalation vulnerability stemming from installer custom actions, scored 7.8. Versions V5.02 and below are affected, and Rockwell Automation has released fixes.
CISA warns CVE-2026-9633 in Rockwell Automation Redundancy Module Configuration Tool lets attackers execute processes with administrator privileges; fix in 10.01.00.
CISA released an ICS advisory for Rockwell Automation Redundancy Module Configuration Tool. CVE-2026-9633 could allow an attacker to escalate privileges and execute processes with administrator rights. Versions 9.00.00 through 10.00.00 are affected, and the vendor shipped a fix in version 10.01.00.
CISA published ICS advisory ICSA-26-239-03 for Rockwell Automation OTTO Fleet Manager versions 2.36.2 and earlier (CVE-2026-75112, CVSS v3 6.8). The flaw involves use of a password hash with insufficient computational effort, reducing the cost for an attacker to perform offline brute-force attacks against stored password hashes. Deployments span critical manufacturing and transportation systems sectors worldwide, with company headquarters in the United States.
NSA, CISA, FBI, DOE, and EPA warn threat actors use AI-assisted scripts and snap7 libraries to access internet-exposed Siemens S7 PLCs in critical infrastructure sectors.
NSA, CISA, FBI, DOE, and EPA issued a joint advisory warning that threat actors combine open-source snap7.dll/python-snap7 libraries with AI-generated scripts to gain read/write access to Siemens S7-200 through S7-1500 PLCs over the S7comm protocol. Actors use Censys and ZoomEye to find internet-exposed devices and abuse default or weak credentials, with activity assessed as persistent reconnaissance and positioning for future write operations. Agencies urge device inventory, patching, removing PLCs from the internet, and hardening; the pattern resembles Iran-linked CyberAv3ngers targeting of Rockwell, Schneider, and Siemens PLCs.
NSA and FBI warn of an active campaign using AI-generated exploit scripts against Siemens S7 PLCs in critical infrastructure sectors.
NSA, FBI and other federal agencies issued an urgent advisory describing an active threat campaign targeting US-based Siemens S7 Series PLCs with AI-generated exploitation scripts disguised as legitimate monitoring tools. Actors use internet scanning to find exposed PLCs in energy, water, and manufacturing sectors, and may be preparing for operational effects. The advisory expands on July warnings of Iran-affiliated hackers targeting PLCs from Siemens, Schneider Electric, Rockwell Automation, and Allen-Bradley.
Iran-linked hackers hit water utilities in New Jersey and Alabama, bringing confirmed US water-infrastructure attacks to at least 12 states.
Iran-linked hackers attacked the Cape May Sewer Department and Woodbine Water Department in New Jersey and the Childersburg Water, Sewer and Gas system in Alabama on July 27, bringing confirmed US water-sector attacks to at least 12 states since late July. The intrusions targeted internet-exposed industrial control systems, including Rockwell Automation PLCs, with roughly 12 hours of impact in New Jersey and no impact on water quality or service. The FBI confirmed seven affected states by July 30, and CISA has urged utilities to remove PLCs from direct internet exposure. New York announced more than $9 million in grants to strengthen water-sector cybersecurity.
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All v
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and < V6.30.016), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus Source Code (All versions), TALON TC Compact (BACnet) (All versions < V3.5.4), TALON TC Modular…
· siemens nucleus net · siemens nucleus readystart v3—
Flawed Authentication Algorithm in Schneider Electric PLC Enables Full Compromise
CVE-2026-3869 is a critical (CVSS 4.0 score 9.2) incorrect implementation of an authentication algorithm (CWE-303) in a Schneider Electric programmable logic controller (PLC), disclosed and patched as part of Schneider Electric's ICS Patch Tuesday release. The flaw is reachable over the network with no privileges or user interaction required, but it carries elevated attack requirements: it comes into play when the PLC is running an application project with a lower application level, which is the configuration precondition for exploitation. An attacker who meets those conditions can defeat the controller's authentication mechanism and cause a complete loss of confidentiality, integrity and availability of the PLC (VC:H/VI:H/VA:H), meaning they could read, modify or disrupt the running control process. Affected users are operators of the impacted Schneider Electric PLC line; the available data does not name the specific model or firmware versions, so operators should confirm their exposure against the official Schneider notification. No public proof-of-concept is known and the flaw is not listed in CISA's KEV, with no reports of exploitation in the wild to date.
· Schneider Electric PLC (specific model line not identified in the available data)large
Remote Denial-of-Service in Rockwell Automation RSLinx Classic via Crafted CIP Packet
CVE-2026-9624 is a denial-of-service flaw in Rockwell Automation's RSLinx Classic industrial communications software: the service fails to properly validate the data length field of incoming CIP packets (CWE-191), so a single crafted packet can crash it. An attacker with network access to the RSLinx service can trigger the crash remotely, with no privileges or user interaction required. The impact is availability-only — the RSLinx service stops and must be manually restarted, interrupting PC-to-controller communications, data collection, or monitoring that depends on it; confidentiality and integrity are unaffected. Any installation running RSLinx Classic where the service is reachable over the network (e.g., engineering workstations or servers in OT/manufacturing environments) is potentially affected. There is currently no known exploitation: the flaw is not in CISA's KEV catalog, no public proof-of-concept exists, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
Denial-of-Service in Rockwell Automation RSLinx Classic via Oversized CIP Packet
CVE-2026-9625 is a denial-of-service flaw in Rockwell Automation's RSLinx Classic industrial communications software, caused by improper handling of input sizes (CWE-120) when parsing CIP (Common Industrial Protocol) messages. An attacker who can reach the RSLinx Classic service over a network can send a single crafted CIP packet containing an oversized embedded message request, which crashes the service. The impact is availability-only: the RSLinx Classic service stops and must be manually restarted to recover, with no evidence of code execution or data compromise (CVSS 4.0 scores availability impact High and all other impacts None). Any organization running RSLinx Classic on workstations or servers that connect operations or maintenance software to Allen-Bradley/Rockwell controllers is potentially affected, particularly where the service is reachable from enterprise or internet-facing networks. As of this writing there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days.
Unauthenticated DoS in Rockwell Automation Logix controllers via CIP length flaw
CVE-2026-9637 is a high-severity denial-of-service vulnerability in Rockwell Automation's Logix controller platform, caused by improper validation of input length during CIP (Common Industrial Protocol) message processing. An attacker who can send crafted CIP messages to an affected controller over the network can trigger the flaw without needing credentials or user interaction. Successful exploitation produces a major nonrecoverable fault (MNRF) that halts the controller and requires a physical power cycle to restore operation, making this an availability-only issue per the CVSS vector. Any site running an affected Logix controller is exposed, with the greatest risk to controllers reachable from untrusted networks such as IT/OT boundary links, VPNs, or internet-exposed EtherNet/IP interfaces. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
· Rockwell Automation Logix platform controllers (the advisory references a table of affected platforms; individual models are not enumerated Affected model/firmware ranges per the Rockwell Automation security advisory; no specific version numbers provided in the source datamass
Out-of-bounds write in Rockwell FactoryTalk Historian Machine Edition allows RCE
Rockwell Automation's FactoryTalk Historian Machine Edition contains an out-of-bounds write (CWE-787) that can be triggered by an attacker who holds low-level (low-privileged) authentication and can reach the historian over an adjacent network, as reflected in the CVSS 4.0 vector (AV:A/PR:L). By sending crafted input to the vulnerable service, the attacker corrupts memory beyond the intended buffer and achieves remote code execution on the host running the historian. Successful exploitation yields high impact to confidentiality, integrity, and availability on the affected system, effectively full compromise of that machine, with no modeled impact spreading to the wider network. Affected users are industrial operators, OEMs/machine builders, and plant sites running FactoryTalk Historian Machine Edition; the affected version ranges are specified in Rockwell Automation's security advisory and are not stated in the source data. Exploitation has not been observed: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days.
· Rockwell Automation FactoryTalk Historian Machine Editionlarge
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case.
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.
DLL Hijacking LPE in Rockwell Automation Redundancy Module Configuration Tool
Rockwell Automation's Redundancy Module Configuration Tool (RM3ConfigTool.exe) is vulnerable to a DLL search-order hijacking issue caused by incorrect default directory permissions (CWE-276). The binary searches directories listed in the system PATH for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users; a local attacker can plant a malicious DLL there, and when an administrator subsequently launches the tool, the malicious DLL is loaded and executes with Administrator or SYSTEM privileges. Exploitation requires low local privileges plus user interaction (an administrator running the tool), and yields full privilege escalation on the affected workstation. Any installation of the Redundancy Module Configuration Tool on Windows where writable PATH directories exist is affected; the available data does not specify affected version ranges. There is no known public proof-of-concept, no entry in the CISA KEV catalog, and EPSS estimates only about a 0.1% probability of exploitation within 30 days.
Everyone-Group Write Permissions in Rockwell ControlFLASH Allow Local Code Execution
The ControlFLASH installer grants write permissions to the Windows 'Everyone' group on the product's installation directory, leaving that directory writable by any local account. An attacker who already has low-privileged access to the machine can plant or modify files in the directory, and when a user launches ControlFLASH the attacker's code runs at that logged-in user's permission level (user interaction is required). This gives the attacker arbitrary code execution of their choosing on the target machine, though within the privileges of the launching user rather than full system-level escalation. Any Windows host where ControlFLASH was installed with these default permissions is affected, typically engineering or maintenance workstations in Rockwell Automation/Allen-Bradley environments. There is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS predicts only a 0.1% chance of exploitation in the next 30 days.
CVE-2026-19471 describes multiple stored cross-site scripting (XSS) flaws in Rockwell Automation's ArmorStart LT, caused by user-supplied input that is not properly sanitized before being stored on the device. An attacker can inject malicious scripts into stored fields, and those scripts execute in the browser of any user who later views the affected page in the device's interface. Per the CVSS 4.0 vector, the attack is carried out over the network and requires no privileges or user interaction beyond viewing the stored content, but the rated impact is limited (low impact to confidentiality, integrity, and availability), meaning an attacker could typically run scripts in other users' sessions within the product's interface rather than compromise the broader system. Affected users are organizations running ArmorStart LT distributed motor-control units whose management or web interfaces are accessed by operators and engineers. As of now there is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.