ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Rockwell, Schneider
Multiple industrial control system (ICS) vulnerabilities have been patched by Siemens, Rockwell Automation, Schneider Electric, and Phoenix Contact. These vulnerabilities affect a variety of ICS/OT products and include issues that could lead to arbitrary code execution, denial of service, unauthorized access, man-in-the-middle attacks, and information disclosure. Siemens addressed critical vulnerabilities in Comos, Sicam T, and Ruggedcom ROX products, as well as high and medium severity issues in other products. Schneider Electric patched vulnerabilities related to Windows Server Update Services and ZombieLoad affecting EcoStruxure Foxboro DCS. Rockwell Automation fixed a high-severity denial of service and SQL injection vulnerabilities. Phoenix Contact addressed multiple vulnerabilities including XSS and authentication issues in its FL SWITCH 2xxx series. These vulnerabilities have been officially patched by the vendors.
AI Analysis
Technical Summary
Industrial cybersecurity vendors Siemens, Rockwell Automation, Schneider Electric, and Phoenix Contact released Patch Tuesday advisories addressing dozens of vulnerabilities in their ICS/OT products. Siemens published 14 advisories, including three rated critical affecting Comos, Sicam T, and Ruggedcom ROX products, with vulnerabilities enabling arbitrary code execution, denial of service, unauthorized access, man-in-the-middle attacks, and sensitive information disclosure. Schneider Electric patched issues in EcoStruxure Foxboro DCS related to WSUS and ZombieLoad vulnerabilities. Rockwell Automation fixed a high-severity denial of service in the 432ES-IG3 GuardLink EtherNet/IP interface and a SQL injection in FactoryTalk DataMosaix Private Cloud. Phoenix Contact addressed multiple XSS, denial of service, authentication, and information exposure vulnerabilities in FL SWITCH 2xxx series switches. These patches mitigate significant risks in critical industrial infrastructure products.
Potential Impact
The vulnerabilities could allow attackers to execute arbitrary code, cause denial of service, gain unauthorized access, perform man-in-the-middle attacks, or obtain sensitive information on affected ICS/OT products. This poses risks to industrial operations and critical infrastructure relying on these products. The severity ratings range from medium to critical depending on the specific vulnerability and product affected.
Mitigation Recommendations
Official patches have been released by Siemens, Rockwell Automation, Schneider Electric, and Phoenix Contact to address these vulnerabilities. Organizations using affected products should apply the vendor-provided updates promptly to mitigate the risks. Since these are on-premises ICS/OT products, remediation requires manual patch deployment following vendor guidance. Patch status is confirmed as fixed by the vendors.
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Rockwell, Schneider
Description
Multiple industrial control system (ICS) vulnerabilities have been patched by Siemens, Rockwell Automation, Schneider Electric, and Phoenix Contact. These vulnerabilities affect a variety of ICS/OT products and include issues that could lead to arbitrary code execution, denial of service, unauthorized access, man-in-the-middle attacks, and information disclosure. Siemens addressed critical vulnerabilities in Comos, Sicam T, and Ruggedcom ROX products, as well as high and medium severity issues in other products. Schneider Electric patched vulnerabilities related to Windows Server Update Services and ZombieLoad affecting EcoStruxure Foxboro DCS. Rockwell Automation fixed a high-severity denial of service and SQL injection vulnerabilities. Phoenix Contact addressed multiple vulnerabilities including XSS and authentication issues in its FL SWITCH 2xxx series. These vulnerabilities have been officially patched by the vendors.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Industrial cybersecurity vendors Siemens, Rockwell Automation, Schneider Electric, and Phoenix Contact released Patch Tuesday advisories addressing dozens of vulnerabilities in their ICS/OT products. Siemens published 14 advisories, including three rated critical affecting Comos, Sicam T, and Ruggedcom ROX products, with vulnerabilities enabling arbitrary code execution, denial of service, unauthorized access, man-in-the-middle attacks, and sensitive information disclosure. Schneider Electric patched issues in EcoStruxure Foxboro DCS related to WSUS and ZombieLoad vulnerabilities. Rockwell Automation fixed a high-severity denial of service in the 432ES-IG3 GuardLink EtherNet/IP interface and a SQL injection in FactoryTalk DataMosaix Private Cloud. Phoenix Contact addressed multiple XSS, denial of service, authentication, and information exposure vulnerabilities in FL SWITCH 2xxx series switches. These patches mitigate significant risks in critical industrial infrastructure products.
Potential Impact
The vulnerabilities could allow attackers to execute arbitrary code, cause denial of service, gain unauthorized access, perform man-in-the-middle attacks, or obtain sensitive information on affected ICS/OT products. This poses risks to industrial operations and critical infrastructure relying on these products. The severity ratings range from medium to critical depending on the specific vulnerability and product affected.
Mitigation Recommendations
Official patches have been released by Siemens, Rockwell Automation, Schneider Electric, and Phoenix Contact to address these vulnerabilities. Organizations using affected products should apply the vendor-provided updates promptly to mitigate the risks. Since these are on-premises ICS/OT products, remediation requires manual patch deployment following vendor guidance. Patch status is confirmed as fixed by the vendors.
Threat ID: 69394257681246c13decfdd7
Added to database: 12/10/2025, 09:50:15 UTC
Last enriched: 07/15/2026, 09:32:43 UTC
Last updated: 09/10/2026, 13:11:40 UTC
Views: 520
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.