July 2026’s ICS Patch Tuesday came in heavier than average. Siemens published nine new advisories, six of which covered critical vulnerabilities. The headline finding is a CVSS 10.0 token invalidation flaw in Siemens Opencenter X that allows unauthenticated attackers to bypass authentication and gain full application access. CISA distributed the advisories and also published three ABB advisories and one Rockwell advisory. Germany’s VDE CERT added five advisories covering Murrelektronik, Mettler Toledo, Codesys, and Wago products.

This is a high-priority patch cycle for OT/ICS environments. Here’s what security teams need to know.

Siemens: CVSS 10.0 Authentication Bypass in Opencenter X

The most urgent finding is a token invalidation vulnerability in Siemens Opencenter X, the company’s building automation and process control platform. CVSS 10.0 is the maximum score on the scoring scale, and in this case it reflects an unauthenticated attack path to full application access.

The vulnerability affects how Opencenter X handles authentication token invalidation. When a session token should be invalidated (on logout or session timeout), the invalidation fails under certain conditions, leaving the token in a valid state. An attacker with network access to the Opencenter X interface can supply a previously-obtained or predicted token value and authenticate without valid credentials.

The practical concern: Opencenter X manages building automation systems and integration between facility management systems. Depending on deployment scope, unauthorised access can mean control over HVAC systems, access control, lighting, fire suppression integration, and in integrated deployments, data centre environmental controls. The platform is deployed in commercial buildings, hospitals, airports, and data centre facilities — environments where unauthorised environmental control has real physical consequences.

Affected versions: Siemens has not publicly confirmed the full affected version range at the time of advisory publication. Customers should consult the advisory directly via the Siemens ProductCERT portal.

Mitigation: Patch to the corrected version released with this advisory. If immediate patching is not feasible:

  • Restrict network access to Opencenter X management interfaces to authorised management workstations only
  • Implement compensating authentication controls at the network layer (VPN with MFA for remote access)
  • Review authentication logs for anomalous access patterns suggesting token reuse or unexpected session establishment

Siemens: Critical Vulnerabilities in Mendix, SIMATIC S7-1500, and Desigo CC

Beyond the Opencenter X CVSS 10 finding, Siemens’ July advisories include critical findings in:

Mendix: Siemens’ low-code application platform has a vulnerability in specific application configurations. Mendix applications are increasingly deployed in manufacturing and logistics environments for workflow automation and monitoring. The specific vulnerability class was not publicly detailed in advance of the advisory; consult the Siemens advisory for CVE details and affected module versions.

SIMATIC S7-1500: The S7-1500 is one of Siemens’ primary industrial PLC families, deployed across manufacturing, water/wastewater, and critical infrastructure environments globally. The July advisory covers a critical flaw in specific firmware versions. The S7-1500 is a persistent target for nation-state actors — Volt Typhoon’s infrastructure pre-positioning campaigns and prior ICS-targeted attacks have repeatedly involved S7 series controllers.

Desigo CC: Siemens’ building automation management platform. Like Opencenter X, it manages facility systems including energy management, HVAC, and building access. A critical vulnerability here has similar physical impact potential to the Opencenter X finding.

Sidis Secured SmartPlug and Cadra round out the critical Siemens findings. Sidis SmartPlug is a secure industrial communication device used in power grid and substation environments. A critical vulnerability here is of particular concern for energy sector operators.

ABB: Three Advisories Distributed via CISA

CISA distributed three ABB advisories alongside the Siemens content. ABB’s portfolio spans power grids, process automation, and motion control, making ABB-specific advisories relevant to energy, oil and gas, and industrial manufacturing environments.

ABB does not pre-disclose vulnerability details before patch availability. The advisories should be retrieved from CISA (cisa.gov/ics-advisories) and cross-referenced with your ABB product inventory.

For ABB environments, the priority assessment process:

  1. Identify your ABB products and versions against the affected systems listed in each advisory.
  2. Check network exposure: ABB industrial systems should not be directly internet-routable, but management interfaces and historian connections may have broader network access than intended.
  3. Assess patch feasibility: Patching OT systems requires change control, outage windows, and vendor support engagement in most environments. If patches cannot be applied immediately, document compensating controls and validate that network isolation mitigates the critical exposure path.

Rockwell Automation: Advisory Released

Rockwell Automation released one advisory this cycle. Rockwell’s Allen-Bradley PLC lines are ubiquitous in North American manufacturing and critical infrastructure. Rockwell advisories consistently rank among the most operationally impactful for North American OT operators given the prevalence of Allen-Bradley hardware in both older (FactoryTalk) and newer (PlantPAx) process control architectures.

Retrieve the specific advisory via CISA’s ICS advisory portal. The advisory should be assessed against Allen-Bradley hardware in your environment, with particular attention to any systems with EtherNet/IP network exposure to less-trusted network segments.

VDE CERT: Codesys, Wago, and Others

Germany’s VDE CERT published five advisories this cycle covering:

  • Codesys: The Codesys runtime environment is the most widely deployed IEC 61131-3 PLC programming environment globally, used across hundreds of controller hardware platforms from dozens of vendors. A Codesys vulnerability typically affects a broad cross-section of ICS hardware — any OT environment with Codesys-based controllers (which includes many Wago, Beckhoff, KUKA, and other vendor devices) should assess exposure.
  • Wago: Wago PLCs and I/O systems are commonly used in building automation, machine safety, and utility environments.
  • Murrelektronik: Industrial networking components.
  • Mettler Toledo: Laboratory and industrial weighing and inspection equipment, relevant to pharmaceutical and food manufacturing environments.

Prioritisation Framework for This Cycle

For OT security teams facing a busy patch cycle:

Immediate assessment (this week):

  • Opencenter X CVSS 10.0 authentication bypass: Identify all deployments, assess network exposure, apply patch or compensating controls
  • S7-1500 advisory: Identify affected firmware versions in your environment
  • Codesys: Identify all devices in your environment running Codesys and the installed runtime version

Short-term (within 30 days):

  • ABB advisories: Full inventory assessment and patch planning
  • Rockwell advisory: Assessment and change control planning for affected hardware
  • Desigo CC and Mendix: Assess deployment scope and criticality

Documentation for compliance:

  • If your environment includes systems subject to NERC CIP (North American power sector), NIS2 (European critical infrastructure), or equivalent regulations, document your assessment and remediation timeline. ICS advisories at CVSS 9.0+ typically trigger mandatory disclosure timelines under these frameworks.

Broader Context

July 2026’s patch volume continues the trend toward higher ICS advisory frequency. CISA’s ICS advisory cadence has roughly doubled since 2023, driven partly by increased researcher attention to OT systems and partly by vendor-initiated discovery using AI-assisted vulnerability research tools. The July 2026 Microsoft Patch Tuesday included over 570 CVEs, with Microsoft explicitly attributing the volume increase to AI-assisted vulnerability discovery — the same dynamic is now visible in ICS advisory counts.

OT environments face an asymmetry: the attack surface is growing at roughly the same rate as the IT advisory cadence, but OT patching cycles are constrained by operational continuity requirements, change control processes, and vendor support timelines that don’t bend to a 30-day remediation window. Network segmentation and monitored compensating controls are not substitutes for patching — they’re the bridge to patching that must be documented and time-bounded rather than accepted as a permanent posture.

Tags
SiemensABBRockwell AutomationCISA ICS-CERTOpencenter XICSSCADApatch Tuesdayauthentication bypassCVSS 10OT security2026ICS advisories