[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqnR9hjG2udNPMqXpMqU8mmmtyFzKpjRNl4JtLFaU3Xs":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"809f5d71-eca9-4a9f-9a62-ee1bc667337c","ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact","ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-phoenix-contact-193709","CISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on SecurityWeek.","Industrial giants Siemens, Schneider Electric, and Phoenix Contact have released advisories detailing numerous vulnerabilities in their Industrial Control System (ICS) and Operational Technology (OT) products. These flaws range from critical code execution and missing authentication to medium-severity issues affecting various devices and software, potentially allowing attackers to gain elevated privileges, execute arbitrary code, or cause denial-of-service conditions. CISA has also published advisories for vulnerabilities in products from Pulsetto, Mira, and Johnson Controls.","Siemens, Schneider Electric, and Phoenix Contact address ICS vulnerabilities in August advisories.","Industrial giants Siemens, Schneider Electric, and Phoenix Contact have published August 2026 Patch Tuesday advisories to inform customers about vulnerabilities found in their ICS products. Siemens has published 10 new advisories. One covers a maximum-severity missing-authentication vulnerability in Simatic IoT2050 Advanced devices. A remote, unauthenticated attacker can exploit it to execute arbitrary code on the underlying server with elevated privileges. A critical code execution vulnerability has also been fixed by Siemens in the Siveillance Video Management Servers. High-severity flaws have been addressed in Solid Edge, Simcenter Nastran, Siemens License Server, Simcenter Femap, Parasolid, and Logo! Soft Comfort. They can be exploited to crash applications, execute arbitrary code, elevate privileges, read arbitrary files, or obtain sensitive information. Medium-severity issues have been resolved in Ruggedcom devices and Desigo controllers. Schneider Electric has published two new advisories describing vulnerabilities in NetBotz 5 and PowerChute Serial Shutdown products. In NetBotz, the company fixed two code\u002Fcommand execution issues, while in PowerChute it patched a flaw allowing excessive authentication attempts, which could lead to disruption or access to system data.Advertisement. Scroll to continue reading. Phoenix Contact has published one advisory for multiple vulnerabilities in PLCnext firmware. The flaws can be exploited by unauthenticated attackers to cause a DoS condition, trigger unexpected behavior, or execute malicious SQL queries. SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Honeywell has published several advisories for its building management system products. The cybersecurity agency CISA published three new advisories on Tuesday and several others earlier this month. The new advisories cover vulnerabilities in Pulsetto, Mira (Quanovate Tech), and Johnson Controls products. Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious ActivitiesOpenAI Unveils New Cybersecurity Model GPT-5.6-CyberMozilla Issues New Firefox GPG Key Following ExposureOpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack ConcernsNew Jersey, Alabama Join States Targeted in Water CyberattacksNovel Private APN Pivot Let Hackers Sabotage Second Polish Energy FacilityCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data Latest News SonicWall Patches Critical Vulnerabilities in Discontinued GMS PlatformCisco Patches Firewall Zero-Day Exploited for DoS AttacksAugust 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DayAdobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic FlawsZoom Patches Zero-Click Code Execution VulnerabilityThe AI Governance Gap Is a Leadership Problem: Waiting Won’t Close ItSAP Patches Critical Code Injection, Memory Corruption VulnerabilitiesUS Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move1Kosmos has named Frank Cohen Chief Revenue Officer.ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-phoenix-contact-2\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F11\u002FICS_Patches.jpg","2026-08-12T07:51:55+00:00","2026-08-12T08:00:24.601503+00:00",8,[18,21,23,25,27,29],{"name":19,"type":20},"Siemens","vendor",{"name":22,"type":20},"Schneider Electric",{"name":24,"type":20},"Phoenix Contact",{"name":26,"type":20},"Honeywell",{"name":28,"type":20},"Johnson Controls",{"name":30,"type":31},"Simatic IoT2050 Advanced","product","d6f63bb8-0801-486a-be7f-171400700454",{"id":32,"icon":34,"name":35,"slug":36},null,"IoT\u002FOT","iot-ot",[38,43,45],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":44},{"id":32,"icon":34,"name":35,"slug":36},{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]