Signal

Multiple critical vulnerabilities disclosed in industrial control systems products

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-03-17 23:49 UTCUpdated 2026-03-18 14:13 UTC
rss
cveexploitsindustrial_control_systemssecurity_advisory
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
[Control Systems] Phoenix Contact Security Advisory (AV26-247)
Canadian Centre for Cyber Security - Alerts · News · cyber.gc.ca · 2026-03-18 14:13 UTC
ALERT CODESYS in Festo Automation Suite: CVSS (Max): 9.8
AusCERT - Bulletins · News · portal.auscert.org.au · 2026-03-17 23:53 UTC
limited source diversity in top sources
Overview

Several high-severity vulnerabilities have been disclosed in key industrial control system (ICS) products from Schneider Electric, Siemens, Phoenix Contact, and Festo.

Entities
Schneider ElectricSiemensPhoenix ContactFestoSCADAPackRemoteConnectEcoStruxure Data Center ExpertSICAM SIAPP SDK
Score total
1.18
Momentum 24h
5
Posts
5
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • Multiple vendors released advisories simultaneously, highlighting a wave of ICS vulnerabilities.
  • Some vulnerabilities allow remote, unauthenticated exploitation, increasing urgency.
  • Patch availability now enables organizations to mitigate risks promptly.
Why it matters
  • Industrial control systems are critical infrastructure components vulnerable to exploitation.
  • High CVSS scores indicate severe risk of remote exploitation without user interaction.
  • Timely patching is essential to prevent potential operational disruptions or safety incidents.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Schneider Electric SCADAPack and RemoteConnect have a critical vulnerability with CVSS 9.8
  • Schneider Electric EcoStruxure Data Center Expert has a vulnerability with CVSS 7.5
  • Siemens SICAM SIAPP SDK contains multiple vulnerabilities with CVSS up to 7.8
  • Phoenix Contact FL SWITCH firmware versions prior to 3.53 contain multiple vulnerabilities
How sources frame it
  • ICS-CERT: neutral
  • Canadian Centre For Cyber Security: neutral
All evidence
All evidence
[Control Systems] Phoenix Contact Security Advisory (AV26-247)
Canadian Centre for Cyber Security - Alerts · cyber.gc.ca · 2026-03-18 14:13 UTC
ALERT CODESYS in Festo Automation Suite: CVSS (Max): 9.8
AusCERT - Bulletins · portal.auscert.org.au · 2026-03-17 23:53 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • Canadian Centre for Cyber Security - Alerts (1)
  • AusCERT - Bulletins (1)
Top origin domains (this list)
  • cyber.gc.ca (1)
  • portal.auscert.org.au (1)