Skip to main content
System Status
Critical 12
|
High 46
|
Medium 1
|
Feed Online
UPDATED: 2026-06-11 00:00 UTC

July 2026 ICS Patch Tuesday: Siemens CVSS 10 Auth Bypass, ABB and Rockwell Advisories

July 2026's ICS Patch Tuesday brought nine Siemens advisories including a CVSS 10.0 authentication bypass in Opencenter X, three ABB advisories, and a Rockwell advisory. Here's what OT/ICS security teams need to prioritise and the operational context for each critical finding.

ICS Patch Tuesday July 2026: Siemens TIA Portal RCE, Schneider IGSS Critical, Rockwell 12 Advisories

July 2026 ICS Patch Tuesday brings a significant advisory load: Siemens releases 18 advisories including a critical TIA Portal remote code execution flaw, Schneider Electric addresses a critical IGSS SCADA vulnerability, and Rockwell Automation publishes 12 advisories covering FactoryTalk and Logix controllers. Prioritisation guidance for OT security teams.

CISA July 2026 ICS Advisories: Satellite Ground Station Terminals and Building Automation Vulnerabilities

CISA's July 2026 ICS advisory batches covered 13 advisories across satellite communication terminals, EV charging management systems, and building automation controllers. This roundup covers the highest-priority items for OT and critical infrastructure security teams.

MQTT Security in IIoT: Authentication, TLS, and Broker Hardening

MQTT is the dominant messaging protocol for Industrial IoT — used in energy monitoring, manufacturing telemetry, building automation, and smart grid applications. Its minimal design and widespread default configurations leave most deployments exposed to unauthenticated access, data interception, and command injection. This guide covers the attack surface and hardening approach.

CISA ICS Advisory Roundup: Inductive Automation Ignition, ICONICS GENESIS64, and Mitsubishi Electric Vulnerabilities June 2026

CISA released nine ICS advisories in June 2026 covering critical and high-severity vulnerabilities in Inductive Automation Ignition, ICONICS/Mitsubishi GENESIS64, and Axis network cameras used in OT environments. This roundup covers the operational risk and remediation priorities.

ICS Patch Tuesday June 2026: Critical Vulnerabilities in Siemens, Honeywell, and Mitsubishi Electric Products

The June 2026 ICS Patch Tuesday cycle brings critical and high-severity advisories affecting Siemens industrial networks, Honeywell building and process control systems, and Mitsubishi Electric PLCs. OT security teams should prioritise triage and remediation planning for affected assets.

Siemens May 2026 ICS Patch Tuesday: Device Takeover in Sentron Energy Meters, Root RCE in Ruggedcom, and 300+ Third-Party Flaws in CN4100

Siemens published 18 security advisories in May 2026's ICS Patch Tuesday, with critical findings in the Sentron 7KT PAC1261 energy data manager, Ruggedcom Rox, Simatic CN4100, and Opcenter RDnL manufacturing platform. This roundup covers the highest-impact advisories with operational guidance for affected sectors.

CISA ICS Advisory Roundup: Kaleris Navis N4, Delta Electronics CNCSoft, and ABB EIBPORT (May 2026)

CISA released eight ICS advisories and one medical device advisory on May 28, 2026, covering critical vulnerabilities in transportation management, CNC motion control, and industrial building automation systems. This analysis covers the highest-impact advisories and operational guidance for affected organisations.

CISA ICS Advisory Bundle: WAGO PFC, AVEVA Plant SCADA, and Beckhoff TwinCAT Vulnerabilities

CISA released seven ICS advisories on May 21, 2026, covering authentication and remote code execution vulnerabilities in WAGO PFC controllers, AVEVA Plant SCADA (formerly Citect), and Beckhoff TwinCAT runtime. Together these advisories affect PLC, SCADA, and automation runtime platforms deployed across manufacturing, energy, and building automation sectors globally.