Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

September 2026 brought security disclosures affecting products from Rockwell Automation, ABB, Siemens and Schneider Electric, but not all were issued on one “Patch Tuesday.” The clearest product-and-version detail in the available September coverage is Schneider Electric’s September 8 notification. CISA bulletins on September 17 and 22 also indexed advisories for products from all four vendors; SecurityWeek reported counts and product names for Siemens and Rockwell. These sources do not establish a complete September vulnerability inventory for every vendor.

What September’s disclosures cover

The September coverage combines three kinds of evidence: Schneider Electric’s September 8 notification listing, SecurityWeek’s report of recent vendor advisories, and CISA’s September 17 and 22 ICS advisory bulletins. CISA’s September 17 bulletin listed eight ICS advisories; its September 22 bulletin listed nine. Those are totals for the respective CISA bulletins, not counts of advisories issued by each vendor.

For administrators, the practical distinction is important: a product appearing in a CISA bulletin is an index entry, not a complete technical description. Confirm CVEs, affected versions, severity, and mitigations in the corresponding vendor notice or linked CISA advisory before making a patch decision.

Which Schneider Electric products and versions are listed?

Schneider Electric’s September 8, 2026 notification lists four newly published items. The product boundaries below come from the vendor portal; consult each linked vendor notice for full remediation instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Product September listing Affected versions or products
EcoStruxure IT Data Center Expert CVE-2026-19233 (SSRF) and CVE-2026-8044 (command argument injection) Version 9.1.2 and prior
PowerLogic T300 CVE-2026-77120; OS command injection Version 2.9.8-5620 and prior
SCADAPack CVE-2026-81861; insufficiently protected credentials SCADAPack 47x, 47xi, 47xd, 470R and 57x; all versions of the listed products
Modicon M580 and Modicon M580 Safety CVE-2026-3869; incorrect implementation of an authentication algorithm M580 below application level 4.00; M580 Safety below application level 4.20

SecurityWeek characterized CVE-2026-3869 as critical and reported a CVSS score of 9.2. Treat that score as SecurityWeek’s reported figure; the September vendor listing identifies the vulnerability and product boundaries, while its notice should be checked for technical details and remediation. SecurityWeek also described the other new Schneider issues as high- or medium-severity categories, but the available summary does not provide a normalized severity comparison across all products.

Do not confuse newly issued September notifications with older items or revised notices on Schneider’s portal. A portal “last updated” date does not, by itself, establish when a vulnerability was first disclosed.

What Siemens advisories were reported?

SecurityWeek reported nine new Siemens advisories since the previous Patch Tuesday, seven of them published on September 8. Its roundup identified four critical-severity advisory areas: Reyrolle 7SR5, Open Interface Services (OIS), Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT. It also named high-severity coverage for Desigo CC, Teamcenter, the Mendix SAML module, and Element Maps.

CISA’s September 22 bulletin separately indexed six Siemens product advisories covering Siveillance Control; SIPLUS and SIMATIC products; the Desigo CC family; Industrial Edge Management; SIMOVE Fleetmanager and SIPLANT; and WTV676/WTV776. The roundup count and CISA index are different reporting views, so they should not be combined into a single product or vulnerability total. The CISA bulletin is an index; use the linked entries and Siemens notices for CVEs, affected versions and mitigations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Rockwell Automation products were named?

SecurityWeek reported that Rockwell Automation had published nine advisories in the week before its September roundup. The products it named were:

  • RSLinx Classic
  • 1756-ENBT
  • FactoryTalk Historian Machine Edition
  • FactoryTalk Activation Manager
  • Redundancy Module Configuration Tool
  • ControlFLASH
  • ArmorStart Distributed Motor Controllers
  • CompactLogix 5380/5480/5580 and GuardLogix 5580
  • Compact GuardLogix 5380

SecurityWeek characterized the RSLinx Classic issues as critical or high severity and the other listed issues as high severity. Its summary does not supply the full affected-version boundaries or mitigation steps for these products. Use the matching Rockwell advisory to establish whether a particular installation is affected and how to remediate it; the nine-advisory figure is SecurityWeek’s count for the stated reporting window, not a complete inventory of Rockwell’s September vulnerabilities.

What ABB coverage is established?

CISA’s September 17 bulletin included an advisory for ABB Ability Edgenius. The bulletin entry alone does not establish the CVE, affected version, severity or mitigation, and the available September coverage does not establish ABB’s total number of advisories. Check the linked CISA entry and ABB notice for those details rather than inferring them from the product name.

How to check whether an installation is affected

Use the exact asset identity and the matching advisory; a product-family name alone is not enough to determine exposure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment
  • Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment, 2nd Edition
  • ABIS BOOK
  • Packt Publishing
  1. Identify the installed product and release. Record the full product or model name, application or firmware level, and version as shown in the asset inventory or product interface.
  2. Match it to the advisory boundary. Compare the exact model and version against the vendor’s affected-products table. For Schneider’s M580 entries, distinguish application level from a generic software version; for SCADAPack, check whether the specific listed model is present.
  3. Read the technical notice. Confirm the CVE, severity and any conditions or operational impact in the vendor advisory. A CISA bulletin listing is a pointer, not a substitute for the advisory’s technical detail.
  4. Follow the vendor’s remediation guidance. Apply the update or mitigation specified for that product and environment. If the advisory’s instructions are unclear or the asset’s version cannot be confirmed, escalate through the vendor’s support or security channel before changing a production control system.
  5. Record the outcome. Document the asset checked, advisory consulted, version match, action taken and verification result so the decision is traceable.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to prioritize the notices

Severity scores and labels are useful signals, not a universal cross-vendor ranking. The September summaries do not provide consistent information about exposure, exploitability, operational context or mitigations across all affected products. Prioritize using the exact vendor advisory together with your own asset criticality and deployment context; do not rank unlike products solely by labels or by Schneider’s reported 9.2 score.

The July 2026 figures sometimes appearing in broader coverage—nine Siemens advisories, two Schneider advisories and twelve Rockwell advisories—refer to a separate earlier reporting window. They are not September totals.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.