OT Intelligence · OT

ICS Patch Tuesday hit M580 Safety and Reyrolle. The exploited device this week is a MikroTik, not a PLC.

4–11 September 2026. Schneider CVE-2026-3869 on Modicon M580 and M580 Safety — firmware and application level both required. Siemens SSA-142885 Reyrolle 7SR5 session-ID exposure (CVE-2026-62645, CVSS 9.8) and Industrial Edge Management account takeover (CVE-2026-18963, 9.1). CISA KEV’d two MikroTik RouterOS bugs on 10 September; CERT.PL says the chain has been live since 2 September. No new Stage 2 ICS malware in public reporting this week.

RWP Ventures · 2026-09-11 · 12 min read · priority 8.6

Bottom line up front

CONFIRMED This week’s public OT calendar was ICS Patch Tuesday paper plus one exploited edge-router class — not a named plant-floor malware event and not a new Stage 2 ICS kill-chain case.

On 8 September Schneider Electric posted SEVD-2026-251-04. CVE-2026-3869 is an incorrect authentication-algorithm implementation on Modicon M580 and Modicon M580 Safety. Schneider scores it CVSS v3.1 9.8 / v4.0 9.2. The vendor’s own words: failure to remediate “may risk establishing an unauthenticated connection” and “loss of confidentiality, integrity and availability of the PLC,” if a project with a lower application level is running. The fix is not a firmware flash by itself. M580 needs firmware 4.10 or above and application level 4.00 or above (Control Expert V15.2+). M580 Safety needs firmware 4.21 or above and application level 4.20 or above (Control Expert V16.0 with HF001). Teams that only bump firmware will still be on the vulnerable application level.

Same day, Siemens ProductCERT published SSA-142885 on Reyrolle 7SR5 protection relays before V2.70. CVE-2026-62645 (CVSS 9.8 / 9.3): the web interface exposes information that can be used to calculate current and past session IDs, which Siemens says can bypass authentication. That is a substation protection product, not a building-management footnote. SSA-503852 (CVE-2026-18963, CVSS 9.1) is an Industrial Edge Management password-reset bypass that lets an unauthenticated remote attacker take over accounts without completing email verification.

The only CONFIRMED in-the-wild activity with a 4–11 September timestamp that OT operators should treat as a live ticket is not a PLC. On 10 September CISA added CVE-2026-67277 and CVE-2026-86060 (MikroTik RouterOS) to KEV. CERT.PL and CCCS AL26-020: the MikroTrick chain has been used against internet-reachable SSH since at least 2 September. That is an edge-device compromise class. It is an IT-to-OT path where plants, water sites, and remote substations use MikroTik as CPE. It is not confirmation that a controller was reprogrammed.

Do not upgrade this week’s PSIRT stack into FrostyGoop. Last week’s live OT threat is unchanged: internet-reachable PLCs and engineering-client abuse named in AA26-097A and AA26-231A.

OT threat posture

Exposure, engineering-path abuse, and now a mass-exploited industrial-grade edge router remain higher confidence than novel ICS malware. Ransomware still hurts plants by killing the Windows and hypervisors OT depends on. No public primary source this week documented a new ladder-logic change or a new ICS-specific wiper.

1. Most significant development

Schneider CVE-2026-3869 on M580 / M580 Safety, because it is a PAC and a safety PAC, it is unauthenticated given the application-level condition, and the remediation will be missed by anyone who treats “flash firmware” as done.

Why this outranked the rest of the week: Reyrolle 7SR5 is as severe on paper (9.8 session calculation) and matters more to transmission/distribution protection engineers, but M580 Safety is the product class already in AA26-097A’s Schneider scope, and the dual firmware-plus-application-level control is an operational failure mode RWP can ticket this week. MikroTik is the exploited box — it is not an ICS product. AVEVA Pipeline Integrity Monitor (ICSA-26-253-01, 10 September) is midstream leak-detection software with a hardcoded key and MD5 password hashes; it is not process control. CareCam Pro (ICSA-26-251-01, 8 September) is a hard-coded bootloader credential requiring physical access. Score for the week: 8.6. Reyrolle-only would have been ~8.7 on severity and ~8.0 on defender actionability without the M580 dual-fix. MikroTik-only belongs in the IT briefing and in section 5 here.

2. Adversary / campaign activity

No new joint USG OT campaign advisory this week. Continuing, still the current hunt set:

CONFIRMED (non-ICS, this week): CERT.PL — attackers chaining MikroTik SSH bugs since at least 2 September, creating a privileged account named ops, source IPs reported as 82.192.72.4 and 103.102.31.18, log artifact user added by ssh:-2@. Help Net Security, citing Shadowserver, reported on the order of 122,500 MikroTik devices with SSH reachable in a 5 September scan window (reachability, not a vulnerability check).

UNKNOWN a 4–11 September named victim with a confirmed ladder-logic or safety-application change.

3. Vulnerabilities and active exploitation

**CONFIRMED (vendor advisory, 8 September — Schneider SEVD-2026-251-*)**

AdvisoryProductCVEWhat it actually is
SEVD-2026-251-04Modicon M580 / M580 SafetyCVE-2026-3869Auth algorithm; unauthenticated connection if application level is below 4.00 / 4.20. CVSS 9.8 / 9.2
SEVD-2026-251-02PowerLogic T300 (ex-Easergy T300) HU250CVE-2026-77120OS command injection to root via authenticated SSH/console. CVSS 8.2 / 8.7. Fix 2.9.8-5621 via Customer Care
SEVD-2026-251-01EcoStruxure IT Data Center Expert ≤9.1.2CVE-2026-19233, CVE-2026-8044SSRF and argument injection on a data-center DCIM product — OT-adjacent cooling/power visibility, not a PLC
SEVD-2026-251-03SCADAPack 47x/47xi/47xd/470R and 57x, all versions listedCVE-2026-81861Insufficiently protected credentials. Read the CSAF before briefing a patch train; the product table says all versions

Schneider also revised four older Modicon notifications the same day (SEVD-2019-134-11 V14, SEVD-2023-010-06 V7, SEVD-2024-044-01 V5, SEVD-2024-317-02 V3), adding MC80 patch language. Those are 2018–2024 CVEs, not new 2026 exploitation.

As of 11 September morning, CISA’s ICS advisory index had not yet republished CVE-2026-3869 as an ICSA. Primary source remains Schneider PSIRT.

CONFIRMED (Siemens ProductCERT, 8 September)

Canadian Centre AV26-890 (8 September) is a useful operator checklist of that Siemens set: Reyrolle 7SR5, Teamcenter, Siveillance Control, SIMATIC AX Runtime, Desigo CC, Industrial Edge Management, SIMOVE/SIPLANT.

CONFIRMED (CISA ICS, this window)

The 3 September CISA stack (Ignition, IXON VPN, Pyramid EtherNet/IP, Logix-adjacent ENBT/ArmorStart/ControlFLASH, OPC UA LDS, Tycon) is last week’s queue. It is not this week’s lead. See 7 September weekly OT.

CONFIRMED (active exploitation, not ICS): MikroTik RouterOS CVE-2026-67277 and CVE-2026-86060, CISA KEV 10 September. Fixed in 6.49.21 / 7.23.4 / 7.24.2. BOD 26-04 forensic-triage expectation applies to FCEB; industrial owners should still image before they wipe. Patching a router that already grew an ops account is not remediation.

NOT this week’s OT story: Cisco Secure FMC CVE-2026-20079 (KEV 9 September, federal due 12 September). It is a firewall-management root. It becomes an IT-to-OT path if that FMC manages the plant DMZ. That is the 10 September Daily Top, not a PLC advisory.

4. ICS / SCADA impact

No CONFIRMED new loss-of-view or loss-of-control event dated 4–11 September in CISA ICS, FBI/EPA, Schneider PSIRT, Siemens ProductCERT, or AVEVA’s PIM bulletin.

What would become process impact, if exploited on an exposed or poorly segmented box:

Prior water PLC tampering (July) and the UK small-generator outage (late July, disclosed August) remain the last well-sourced availability hits. They are not this week’s news.

5. IT-to-OT exposure

Three doors this week, in the order operators can actually hunt:

  1. MikroTik RouterOS with WAN SSH. Industrial parks, lift stations, and small substations buy these. Hunt: internet-facing 22/TCP on RouterOS banners; local user ops; log line user added by ssh:-2@; unexpected policy-mask changes. If you find ops, treat the device as owned — do not just upgrade. Then take SSH off the internet.
  2. Industrial Edge Management and IXON-class remote access (IXON was 3 September; IEM is 8 September). Password-reset and VPN-client bugs are how a commodity IT session becomes a machine session without touching a coil.
  3. Cisco FMC and other plant-DMZ managers (CVE-2026-20079). If FMC is how you push rules onto the OT firewall, root on FMC is root on the policy. Patch plus the Talos post-compromise clusters — see the Daily Top.

Ignition, engineering workstations, and internet-facing 44818/102/502/2222 remain the standing hunt from AA26-097A / AA26-231A. That hunt does not reset because Patch Tuesday landed.

6. Sector impact

7. Defensive priorities

  1. Internet-facing PLC eradication — still number one. VPN or jump host, never the controller. AA26-097A / AA26-231A have not been withdrawn.
  2. M580 / M580 Safety: confirm firmware and application level. Firmware 4.10/4.21 without application level 4.00/4.20 is not the Schneider fix.
  3. Reyrolle 7SR5 to V2.70 on a maintenance window that protection engineering owns. Do not “disable the web server” as a clever shortcut until the protection engineer says that path is unused.
  4. IEM Pro/Virtual to the trains in SSA-503852, or block the reset-credentials path and accept that password reset is off.
  5. MikroTik: patch, then hunt ops / ssh:-2@. Pull WAN SSH. Image before wipe if the box sits in front of a plant or a lift station.
  6. AVEVA PIM 2025 SP1 P2, migrate project files, rotate passwords, restrict read ACLs on old files.
  7. Work last week’s 3 September ICSA pile if it is still in the queue: IXON, Ignition, then device firmware. Do not drop it because M580 arrived.
  8. Do not wait for ICS-specific malware. Dragos Q2 already told you ransomware did not need Stage 2.

8. What changed from last week

Last week (ending 7 September) was CISA’s 1–3 September ICS stack — Logix CIP DoS CVE-2026-9637, Ignition, IXON, Pyramid EtherNet/IP — and no new Stage 2 malware. This week added vendor Patch Tuesday: Schneider M580 Safety auth, Siemens Reyrolle and IEM, AVEVA PIM via CISA on the 10th, and a KEV on MikroTik that is actually being exploited. No new USG PLC campaign update. No new FBI/EPA water PSA. No new industrial-ransomware quarter. AA26-231A is 23 days old; the new public text is CSO’s 8 September implementation note, not a new victim.

9. What OT defenders should watch next

Whether CISA republishes CVE-2026-3869 as an ICSA — that will drive the federal/contractor ticket even though Schneider already shipped the fix. Whether Reyrolle 7SR5 or IEM CVE-2026-18963 grows an in-the-wild note. Whether MikroTik ops shows up in industrial ASN space, not just consumer CPE. Q3 industrial ransomware counts. Any AA26-097A or water-PSA refresh.

10. RWP assessment

High confidence: this week is ICS Patch Tuesday hygiene plus an exploited edge router. High confidence: exposed controllers and engineering paths in AA26-097A / AA26-231A remain the incident class that has evidence. High confidence: flashing M580 firmware without raising application level leaves CVE-2026-3869 open. Moderate confidence: a non-trivial number of industrial WAN edges are MikroTik with SSH on the internet; CERT.PL’s ops artifact is the hunt, not a plant-floor IOC. Low confidence: a new OT malware family dropped in the last seven days. Labeling a manufacturer ransomware victim, or a MikroTik CPE, as “OT compromise” without process evidence remains a briefing error.

This assessment covers 4–11 September 2026 and was published 11 September 2026.

Sources

  1. Schneider Electric — SEVD-2026-251-04 Modicon M580 / M580 Safety CVE-2026-3869
  2. Schneider Electric — Security notifications 8 September 2026
  3. Schneider Electric — SEVD-2026-251-02 PowerLogic T300 CVE-2026-77120
  4. Siemens ProductCERT — SSA-142885 Reyrolle 7SR5 before V2.70
  5. Siemens ProductCERT — SSA-503852 Industrial Edge Management CVE-2026-18963
  6. Siemens ProductCERT — SSA-254516 OIS arbitrary file upload
  7. Siemens ProductCERT — Advisories RSS 8 September 2026
  8. CISA — ICSA-26-253-01 AVEVA Pipeline Integrity Monitor
  9. CISA — Adds two KEVs 10 September 2026 (MikroTik)
  10. CISA — ICS Advisories
  11. CERT.PL — MikroTik RouterOS actively exploited
  12. Canadian Centre for Cyber Security — AL26-020 MikroTik RouterOS
  13. SecurityWeek — ICS Patch Tuesday Schneider Siemens AVEVA Rockwell
  14. CISA — AA26-231A Defending against an active threat to Siemens S7
  15. CSO Online — Harden S7 without disrupting production
  16. RWP — Daily Top Cisco FMC CVE-2026-20079
  17. RWP — Weekly OT 7 September 2026