Schneider Electric’s most severe newly addressed issue in September 2026 was a CVSS 9.2 authentication vulnerability affecting Modicon M580 and M580 Safety controllers. Siemens issued advisories spanning critical issues in protection, industrial-edge and fleet-management products. CISA then published additional dated ICS bulletins on September 15, 17 and 22, so the September 9 overview was not the complete chronological list. Because fixes and mitigations depend on the product and version, operators should confirm details in the relevant vendor advisory and coordinate changes through their OT change-control process.
What Schneider Electric and Siemens addressed
The September 2026 coverage counted four new Schneider Electric security advisories and four updated advisories. Siemens issued nine new advisories and updated nine others. The table summarizes the products and severity information reported for the principal issues; it does not identify every affected version or establish that every deployment of a named product is vulnerable.
| Vendor | New and updated coverage | Products and reported severity |
|---|---|---|
| Schneider Electric | Four new advisories; four updated advisories | Critical: Modicon M580 and M580 Safety controllers, CVE-2026-3869, CVSS 9.2; an authentication vulnerability. High: PowerLogic T300 (formerly Easergy T300 RTU) and EcoStruxure IT Data Center Expert. Medium: SCADAPack x70. The four updated advisories added patches for the Modicon MC80 controller. |
| Siemens | Nine new advisories; nine updated advisories | Critical advisories: Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, and SIMOVE Fleetmanager/SIPLANT. High advisories: Desigo CC, Teamcenter, the Mendix SAML module, and Element Maps. Updated coverage also addressed products affected by the Copy Fail Linux kernel vulnerability, CVE-2026-31431, reported at CVSS 7.8 with the potential to provide root-shell access. |
The CVSS figures above are the ratings reported in the September 2026 coverage: 9.2 for Schneider Electric’s CVE-2026-3869 and 7.8 for Siemens coverage of CVE-2026-31431. A CVSS score helps compare technical severity; it does not by itself tell an operator whether a particular installation is affected or how urgently a change can safely be deployed.
Which products appeared in CISA’s later September bulletins?
CISA’s September 15, 17 and 22, 2026 bulletins added dated cross-references to Schneider Electric and Siemens advisories. CISA’s stated guidance was: “CISA encourages users and administrators to review these ICS Advisories for technical details and mitigations.” The bulletins show why a single early-month summary should not be treated as the full September sequence.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
- The series LPJ-30SP is a class J, low-peak, dual-element, current limiting, time-delay fuse.
- These fuses are generally used in power panelboards, branch circuit breaker panelboard mains, machinery disconnects, and industrial controls, among other applications.
- Dual element fuses feature separate overload and short-circuit elements to provide the same short circuit protection as a fast-acting fuse with the added benefit of letting inrush currents pass without opening the fuse.
- This means they provide 50% more protection than any other listed fuse on the market.
- September 15: Schneider Electric SCADAPack x70; Siemens Reyrolle 7SR5, Mendix SAML, and Teamcenter.
- September 17: Schneider Electric Modicon M340, NetBotz 5 750/755, and PowerChute Serial Shutdown.
- September 22: Siemens Siveillance Control, SIPLUS/SIMATIC, Desigo CC, Industrial Edge Management, SIMOVE Fleetmanager/SIPLANT, and WTV676/WTV776.
These are products named in the dated CISA bulletins, not a claim that every model or software version is affected. Check the corresponding advisory for the applicable product scope and remediation.
How to determine whether a controller or system is affected
A product family name alone is not enough to establish exposure. For each asset, match the exact product, model and installed version against the vendor’s advisory. Then check the advisory’s stated fixed version or mitigation and any conditions that determine applicability. The September coverage does not provide exact fixed versions, so those details must come from the relevant Schneider Electric or Siemens advisory.
Rank #2
- OEM part, new in box and pack of 10 units
- Part number: KLDR005
- Size: 10.3 x 38.1 mm
- Inventory the exact controller, relay, platform or management-software version in use.
- Match that version and configuration to the vendor advisory, including any applicability conditions.
- Identify the prescribed fixed version or mitigation; do not infer a version number from the product name or severity rating.
- For Siemens products listed in the Copy Fail update coverage, check the advisory to determine whether the installed product and its underlying components are in scope.
What should OT teams patch first?
Use severity to identify issues that warrant prompt review, then make deployment order depend on actual exposure and operational risk. The CVSS 9.2 Modicon M580/M580 Safety authentication issue is the highest-scoring newly addressed issue identified in this September coverage. Siemens’ critical advisories also merit close review across protection, industrial-edge and fleet-management roles. Neither score alone determines whether a given asset is exposed or whether immediate deployment is safe.
- Confirm applicability. Compare the installed product and version with the vendor advisory before scheduling a patch.
- Review mitigations and fixed versions. Use the vendor’s product-specific instructions; the September overview does not state exact fixed versions.
- Assess operational impact. Consider the role of the affected system, dependencies, maintenance windows and the consequences of interrupting a live process.
- Plan and validate the change. Coordinate deployment, testing and recovery steps through the site’s ICS change-control process.
- Track later notices. Include the September 15, 17 and 22 CISA bulletins in the review rather than relying only on the early-month overview.
The practical priority is therefore not simply “patch the highest CVSS number first.” It is to identify affected assets, follow the vendor’s specified remediation, and deploy it under controls appropriate to the system’s role and availability requirements.
Quick Recap
Best Value
- 30A 250Vac/125Vdc
- Current-limiting. dual-element design
- Time-delay, Class RK5 fuse
- Interrupting Ratings AC: 200 kA rms symmetrical
Rank #4
- HAOKETAI 5*20mm fuse is designed for 125V 10A circuit
- 10 amp fuse specification parameters voltage (125V) and current (10A)
- Fuse kitmake it suitable for small electronic devices, power modules and other scenarios.LED drivers, small appliances, industrial control boards, chargers
- mini fuses 0.19x0.78 Inch,Each pack contains 20 fuses and is packed in an anti-static transparent bag
- HAOKETAI fuse mechanism is used to achieve current protection. When the current is abnormal, the automatic fuse will quickly cut off the circuit to ensure safety.
Rank #3
- Rating:[Exact 10x38mm Replacement] Designed as a direct drop-in replacement for standard RT18-32 and RO15 fuses. Measures exactly 10x38mm (approx. 3/8" x 1-1/2"). Please check your blown fuse's markings and size before ordering to ensure a perfect fit for your DIN rail holder. 500VAC 100kA, 690VAC 50kA
- [High Breaking Capacity 100kA] Engineered for extreme safety. This RT18-32 fuse features an impressive 100kA interrupting rating at 500V AC. It safely and instantly clears severe short circuits, preventing catastrophic damage to your industrial control panels and wiring.
- [Standard gG Class Protection] What is it used for? Designed as a gG class fuse for general-purpose applications. It provides excellent full-range protection for 50Hz/60Hz AC electrical distribution systems, cables, and motor circuits against both overloads and short circuits.
- [IEC 60269 Certified Reliability] Built to strict international standards. Compliant with IEC(EN)60269 and CE certified, ensuring consistent, heavy-duty performance. Features low power dissipation (≤3W) and operates stably in environments from -5°C to 35°C.
- [10-Pack Value Set] Includes 10 pieces of CE-certified ceramic fuses in one package. This provides excellent value for bulk maintenance needs or keeping spare parts in your toolbox. Avoid machine downtime by having reliable AC replacements ready when you need them.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

