July 2026 ICS Patch Tuesday represents a significant advisory volume across the three largest ICS vendors. CISA released 19 advisories — the highest count since the March 2026 cycle — with Siemens accounting for 18 and Rockwell Automation publishing a separate 12-advisory bundle directly. Schneider Electric released its monthly bulletin alongside the cycle. OT security teams should prioritise the TIA Portal and IGSS items this week.
Siemens: 18 Advisories, Critical TIA Portal RCE
Siemens’ July 2026 advisory package is one of its larger monthly releases. The critical item is a remote code execution vulnerability in TIA Portal, the engineering workstation software used to program Siemens S7 PLCs, HMIs, and drives across manufacturing, energy, and water infrastructure.
SSA-742091: TIA Portal Remote Code Execution via Malicious Project File (CVE-2026-38944)
CVSS v3.1 Base Score: 9.8 (Critical)
The vulnerability resides in TIA Portal’s project file parser. A maliciously crafted .ap19 or .ap20 project file triggers a heap buffer overflow when opened by TIA Portal V18 and V19. Successful exploitation results in arbitrary code execution in the context of the logged-in engineering workstation user — typically a domain account with elevated privileges on the OT network.
Affected versions:
- TIA Portal V18 prior to V18 Update 4
- TIA Portal V19 prior to V19 Update 2
Attack scenario: The most realistic exploitation path is a supply chain or phishing attack where a malicious project file is delivered to an engineer via email or a compromised file share. TIA Portal project files are routinely exchanged between OT engineers, contractors, and system integrators, creating a natural delivery vector. The vulnerability does not require network access to the OT network — it executes on the engineering workstation during file open.
Mitigation:
- Apply the patch immediately: TIA Portal V18 Update 4 and V19 Update 2
- Implement strict controls on project file sharing — project files should only be opened from trusted, verified sources
- Scan TIA Portal project files received from external parties before opening
- Ensure engineering workstations run EDR with coverage of TIA Portal processes
- Consider opening untrusted project files in an isolated virtual machine or sandbox
CISA advisory: ICSA-26-198-01
SSA-619443: Siemens SCALANCE W (Industrial Wireless LAN) Authentication Bypass (CVE-2026-34711)
CVSS v3.1 Base Score: 9.1 (Critical)
SCALANCE W industrial wireless access points (WAP 721, WAP 722, WAP 748-1 prior to V3.0.2) contain an authentication bypass in the web management interface. An unauthenticated attacker on the same network segment can access the management interface without credentials and modify device configuration, including VLAN assignments and wireless security parameters.
Mitigation:
- Update to SCALANCE W firmware V3.0.2 or later
- Restrict management interface access to dedicated management VLANs with strict ACLs
- Disable HTTP management interface — use HTTPS only
CISA advisory: ICSA-26-198-03
Additional Siemens Advisories (Summary)
| Advisory | Product | CVSS | Type |
|---|---|---|---|
| ICSA-26-198-04 | SINEC INS | 8.8 | SQL Injection |
| ICSA-26-198-05 | SIMATIC WinCC | 8.1 | Path Traversal leading to file disclosure |
| ICSA-26-198-06 | SIPROTEC 5 | 7.5 | Denial-of-service via malformed IEC 61850 packet |
| ICSA-26-198-07 | SICAM Q200 | 7.4 | Missing authentication for firmware update endpoint |
| ICSA-26-198-08 | SINEMA Remote Connect | 7.3 | SSRF in network topology viewer |
| ICSA-26-198-09 | RUGGEDCOM ROX | 7.1 | Command injection (requires authentication) |
| ICSA-26-198-10 | S7-1500 TM NPU | 6.8 | Heap corruption in OPC-UA server |
Full Siemens advisories: productcert.siemens.com
Schneider Electric: IGSS SCADA Critical RCE
SEVD-2026-196-01: IGSS (Interactive Graphical SCADA System) Unauthenticated RCE (CVE-2026-41203)
CVSS v3.1 Base Score: 9.8 (Critical)
Schneider Electric’s IGSS SCADA platform contains a critical vulnerability in the IGSS Data Collector service (dc.exe). The service listens on TCP port 12397 and processes incoming data packets without authentication. A specially crafted packet exploits a stack buffer overflow in the packet parsing code, resulting in unauthenticated remote code execution on the SCADA server.
Affected versions:
- IGSS V16.0.0.23304 and earlier
Deployment context: IGSS is deployed in water and wastewater treatment, building automation, food and beverage production, and small-to-medium manufacturing environments. The Data Collector service is a core component and cannot be disabled without losing SCADA functionality.
Mitigations:
- Apply IGSS V16.0.0.23305 (released July 8, 2026)
- If patching cannot be completed immediately: block TCP 12397 at the network perimeter and restrict access to the SCADA server to trusted engineering workstations only
- Place IGSS servers behind an application-layer firewall or data diode where the SCADA server initiates all external connections
- Monitor for anomalous connections to port 12397 — this port should only receive connections from authorised IGSS clients
The vulnerability is rated Internet-facing-possible in Schneider’s advisory, noting that some IGSS deployments have the Data Collector service inadvertently exposed due to flat OT network architectures.
CISA advisory: ICSA-26-198-15
Additional Schneider Electric Advisories
| Advisory | Product | CVSS | Type |
|---|---|---|---|
| SEVD-2026-196-02 | EcoStruxure Control Expert | 8.3 | Improper access control on diagnostic port |
| SEVD-2026-196-03 | Modicon M340 | 7.5 | Cleartext transmission of session credentials |
| SEVD-2026-196-04 | PowerLogic ION Setup | 7.1 | Uncontrolled search path element (DLL hijacking) |
Rockwell Automation: 12 Advisories
Rockwell published 12 advisories outside the standard CISA release window — directly via their Product Security Incident Response Team (PSIRT) portal. The most significant items cover FactoryTalk View SE and Logix controllers.
SD1912: FactoryTalk View SE Privilege Escalation (CVE-2026-39512)
CVSS v3.1 Base Score: 8.8 (High)
FactoryTalk View SE (Site Edition) V13.0 and earlier contain a privilege escalation vulnerability in the authentication handling for FactoryTalk Security. An authenticated user with Operator-level access can escalate privileges to Administrator by manipulating a parameter in the login sequence. FactoryTalk View SE is widely used as the HMI platform for Allen-Bradley and Logix-based automation systems.
Mitigation:
- Update to FactoryTalk View SE V13.0 CPR 9 SR 15 or later
- Implement network access controls to restrict FactoryTalk View SE servers to known HMI client IPs
SD1908: Logix 5000 Controllers Denial of Service (CVE-2026-40217)
CVSS v3.1 Base Score: 7.5 (High)
CompactLogix, ControlLogix, and GuardLogix controllers running firmware V35 and earlier are vulnerable to a denial-of-service condition triggered by a malformed EtherNet/IP (CIP) packet. The vulnerability causes the controller to enter a fault state requiring manual recovery. In manufacturing environments, this translates directly to an unplanned production stoppage.
Affected firmware: V35.000 and earlier (multiple Logix 5000 platform variants)
Mitigation:
- Update to Logix 5000 firmware V36.000 or later (available via Rockwell FactoryTalk Update Manager)
- Implement CIP traffic filtering to permit EtherNet/IP only from authorised SCADA and HMI systems
- Deploy Claroty, Dragos, or Nozomi for passive monitoring of CIP traffic anomalies
Additional Rockwell Advisories (Summary)
| Advisory | Product | CVSS | Type |
|---|---|---|---|
| SD1907 | Arena Simulation | 7.8 | Memory corruption in file parser |
| SD1906 | FactoryTalk Optix | 7.5 | Path traversal in file serving component |
| SD1905 | Studio 5000 Logix Designer | 7.3 | Unsafe deserialization in add-on profile |
| SD1904 | DataMosaix Private Cloud | 6.9 | SSRF |
| SD1903 | FactoryTalk Analytics | 6.7 | Insufficient logging of admin actions |
| SD1902 | Kinetix 5700 Servo Drive | 6.5 | Cleartext credentials in configuration file |
| SD1901 | FactoryTalk Remote Access | 6.3 | Missing rate limiting on authentication endpoint |
| SD1900 | Plex Industrial IoT | 5.9 | Improper certificate validation |
Full Rockwell advisories: Rockwell Automation PSIRT portal
Prioritisation for OT Security Teams
Given typical OT patching constraints, prioritise in this order:
Immediate (48-72 hours):
- CVE-2026-38944 (TIA Portal): Engineering workstations are often the least-protected assets in OT environments and this is a client-side file-parsing vulnerability — high exploitation likelihood. Apply Update 4/Update 2 now.
- CVE-2026-41203 (IGSS): Unauthenticated network-exposed RCE. If patch cannot be applied immediately, implement emergency network controls to block port 12397 from all but authorised IGSS clients.
Within current maintenance window (2-4 weeks): 3. CVE-2026-34711 (SCALANCE W): Authentication bypass on industrial wireless APs — less immediately exploitable if management interfaces are on segmented management VLANs. 4. CVE-2026-39512 (FactoryTalk View SE): Privilege escalation requiring authenticated access — lower urgency if Operator accounts are properly vettted. 5. CVE-2026-40217 (Logix 5000): DoS risk; assess based on criticality of affected production lines.
Next scheduled maintenance cycle: 6-12. Remaining Rockwell and Schneider advisories; prioritise by CVSS score and network exposure of affected systems.
CISA’s advisories are available at cisa.gov/ics-advisories. Siemens advisories at cert-portal.siemens.com. Schneider advisories at se.com/psirt.