Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

September 2026 ICS Patch Tuesday coverage is a cross-vendor roundup, not a single coordinated CISA release. CISA separately announced eight ICS advisories on September 15, including notices for Schneider Electric SCADAPack x70 and Siemens Reyrolle 7SR5, Mendix SAML and Teamcenter. To find out whether a particular industrial system needs attention, match its exact model and installed version to the relevant vendor advisory; a product-family name alone does not establish that a deployment is affected.

What does September 2026 ICS Patch Tuesday cover?

A September 9 roundup from the Industrial Control Systems Cybersecurity Conference describes security notices and remediation across Schneider Electric, Siemens, AVEVA and Rockwell Automation. It provides cross-vendor context, but it is not the same publication stream as CISA’s dated advisories. Exact affected versions and remediation instructions must come from the applicable vendor notice.

The distinction matters operationally: a roundup may help identify which manufacturers or product families to check, while a vendor advisory is the source to use for product-specific applicability and remediation. The reviewed roundup does not establish a complete, comparable inventory of CVEs, affected versions and fixes across all the named vendors.

Which ICS advisories did CISA release on September 15?

CISA said its September 15, 2026 release included eight ICS advisories. The bulletin listed these product or service areas:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Schneider Electric SCADAPack x70 Products
  • Siemens Reyrolle 7SR5
  • Siemens Mendix SAML
  • Siemens Teamcenter
  • Digital Watchdog VMAX/DVR/NVR
  • Wärtsilä FOS-Onboard
  • mySCADA myPRO Manager
  • CareCam CM2507

This is the list in that particular September 15 bulletin, not a claim that it covers every industrial security notice published during September. The roundup’s vendor coverage and CISA’s release should be treated as related but distinct sources.

How can you check whether an industrial system is affected?

  1. Identify the deployed system. Record the manufacturer, exact product and model, and installed software or firmware version. Include relevant configuration details if the vendor advisory uses them to define exposure.
  2. Find the matching vendor security notice. Use the vendor’s current advisory or security-notifications portal. For Schneider Electric, its Security notifications portal contains dated records and links to related technical documents. The live listing includes a September 8, 2026 notice for EcoStruxure IT Data Center Expert; that is a separate record and should not be confused with the SCADAPack x70 item in CISA’s September 15 bulletin.
  3. Compare the notice’s scope with the installed system. Check the exact affected models and versions, any stated exposure conditions, and whether the notice identifies a fixed version or a mitigation. A match on a broad family name is not enough to conclude that a specific installation is vulnerable.
  4. Plan remediation through site change control. Review the vendor’s fix or mitigation and coordinate any production change through the site’s normal operational review. CISA encourages users and administrators to review its ICS advisories for technical details and mitigations; the September bulletin does not itself establish that patching every named system immediately is safe or mandatory.

What is known about the named vendors?

Schneider Electric

CISA’s September 15 list includes SCADAPack x70 Products. Schneider’s Security notifications portal is a primary route to dated vendor records and linked technical material. The reviewed evidence does not provide a complete SCADAPack affected-version, CVE and fixed-version breakdown, so use the matching vendor notification rather than inferring those details from the family name or roundup.

Siemens

CISA’s bulletin names three separate Siemens advisory subjects: Reyrolle 7SR5, Mendix SAML and Teamcenter. Those names identify the listed product areas, but do not by themselves establish which installations or versions are affected. Check the corresponding Siemens notices for the exact scope and remediation.

AVEVA and Rockwell Automation

The September roundup includes AVEVA and Rockwell Automation in its cross-vendor coverage. The evidence available here does not establish a complete set of exact advisory identifiers, CVEs, affected versions or fixed versions for either vendor. In particular, it does not support a product-by-product Rockwell remediation table. Consult the current vendor advisory before deciding that a particular installation is in scope.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should you interpret severity and patch timing?

A vendor-published severity score can help characterize a vulnerability, but it is not a site-specific risk assessment and does not determine when a production system can safely be changed. Applicability depends on the exact product and version and any conditions stated in the advisory; patch timing also needs to account for the site’s operational review and change-control process.

Do not infer active exploitation, a zero-day, a universal emergency or a mandatory CISA patch order from a roundup or from the September 15 advisory count. Such claims require explicit support in the applicable primary advisory. The count of eight refers to advisories in CISA’s September 15 release, not to the number of vulnerabilities, affected installations or incidents.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which sources should guide remediation?

Use the September 9 Industrial Control Systems Cybersecurity Conference roundup for its broad account of the month’s cross-vendor coverage. Use CISA’s September 15 bulletin to verify which eight notices CISA released on that date. For affected versions, technical conditions and a fix or mitigation, follow the applicable vendor advisory; Schneider Electric’s Security notifications portal provides dated records and linked documents for its products. Keep announcement, notification and update dates distinct when the individual source gives more than one.

Best Value
Sale
Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment
  • Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment, 2nd Edition
  • ABIS BOOK
  • Packt Publishing

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.