July 2026 ICS Patch Tuesday represents a significant advisory volume across the three largest ICS vendors. CISA released 19 advisories — the highest count since the March 2026 cycle — with Siemens accounting for 18 and Rockwell Automation publishing a separate 12-advisory bundle directly. Schneider Electric released its monthly bulletin alongside the cycle. OT security teams should prioritise the TIA Portal and IGSS items this week.

Siemens: 18 Advisories, Critical TIA Portal RCE

Siemens’ July 2026 advisory package is one of its larger monthly releases. The critical item is a remote code execution vulnerability in TIA Portal, the engineering workstation software used to program Siemens S7 PLCs, HMIs, and drives across manufacturing, energy, and water infrastructure.

SSA-742091: TIA Portal Remote Code Execution via Malicious Project File (CVE-2026-38944)

CVSS v3.1 Base Score: 9.8 (Critical)

The vulnerability resides in TIA Portal’s project file parser. A maliciously crafted .ap19 or .ap20 project file triggers a heap buffer overflow when opened by TIA Portal V18 and V19. Successful exploitation results in arbitrary code execution in the context of the logged-in engineering workstation user — typically a domain account with elevated privileges on the OT network.

Affected versions:

  • TIA Portal V18 prior to V18 Update 4
  • TIA Portal V19 prior to V19 Update 2

Attack scenario: The most realistic exploitation path is a supply chain or phishing attack where a malicious project file is delivered to an engineer via email or a compromised file share. TIA Portal project files are routinely exchanged between OT engineers, contractors, and system integrators, creating a natural delivery vector. The vulnerability does not require network access to the OT network — it executes on the engineering workstation during file open.

Mitigation:

  • Apply the patch immediately: TIA Portal V18 Update 4 and V19 Update 2
  • Implement strict controls on project file sharing — project files should only be opened from trusted, verified sources
  • Scan TIA Portal project files received from external parties before opening
  • Ensure engineering workstations run EDR with coverage of TIA Portal processes
  • Consider opening untrusted project files in an isolated virtual machine or sandbox

CISA advisory: ICSA-26-198-01


SSA-619443: Siemens SCALANCE W (Industrial Wireless LAN) Authentication Bypass (CVE-2026-34711)

CVSS v3.1 Base Score: 9.1 (Critical)

SCALANCE W industrial wireless access points (WAP 721, WAP 722, WAP 748-1 prior to V3.0.2) contain an authentication bypass in the web management interface. An unauthenticated attacker on the same network segment can access the management interface without credentials and modify device configuration, including VLAN assignments and wireless security parameters.

Mitigation:

  • Update to SCALANCE W firmware V3.0.2 or later
  • Restrict management interface access to dedicated management VLANs with strict ACLs
  • Disable HTTP management interface — use HTTPS only

CISA advisory: ICSA-26-198-03


Additional Siemens Advisories (Summary)

AdvisoryProductCVSSType
ICSA-26-198-04SINEC INS8.8SQL Injection
ICSA-26-198-05SIMATIC WinCC8.1Path Traversal leading to file disclosure
ICSA-26-198-06SIPROTEC 57.5Denial-of-service via malformed IEC 61850 packet
ICSA-26-198-07SICAM Q2007.4Missing authentication for firmware update endpoint
ICSA-26-198-08SINEMA Remote Connect7.3SSRF in network topology viewer
ICSA-26-198-09RUGGEDCOM ROX7.1Command injection (requires authentication)
ICSA-26-198-10S7-1500 TM NPU6.8Heap corruption in OPC-UA server

Full Siemens advisories: productcert.siemens.com


Schneider Electric: IGSS SCADA Critical RCE

SEVD-2026-196-01: IGSS (Interactive Graphical SCADA System) Unauthenticated RCE (CVE-2026-41203)

CVSS v3.1 Base Score: 9.8 (Critical)

Schneider Electric’s IGSS SCADA platform contains a critical vulnerability in the IGSS Data Collector service (dc.exe). The service listens on TCP port 12397 and processes incoming data packets without authentication. A specially crafted packet exploits a stack buffer overflow in the packet parsing code, resulting in unauthenticated remote code execution on the SCADA server.

Affected versions:

  • IGSS V16.0.0.23304 and earlier

Deployment context: IGSS is deployed in water and wastewater treatment, building automation, food and beverage production, and small-to-medium manufacturing environments. The Data Collector service is a core component and cannot be disabled without losing SCADA functionality.

Mitigations:

  • Apply IGSS V16.0.0.23305 (released July 8, 2026)
  • If patching cannot be completed immediately: block TCP 12397 at the network perimeter and restrict access to the SCADA server to trusted engineering workstations only
  • Place IGSS servers behind an application-layer firewall or data diode where the SCADA server initiates all external connections
  • Monitor for anomalous connections to port 12397 — this port should only receive connections from authorised IGSS clients

The vulnerability is rated Internet-facing-possible in Schneider’s advisory, noting that some IGSS deployments have the Data Collector service inadvertently exposed due to flat OT network architectures.

CISA advisory: ICSA-26-198-15


Additional Schneider Electric Advisories

AdvisoryProductCVSSType
SEVD-2026-196-02EcoStruxure Control Expert8.3Improper access control on diagnostic port
SEVD-2026-196-03Modicon M3407.5Cleartext transmission of session credentials
SEVD-2026-196-04PowerLogic ION Setup7.1Uncontrolled search path element (DLL hijacking)

Rockwell Automation: 12 Advisories

Rockwell published 12 advisories outside the standard CISA release window — directly via their Product Security Incident Response Team (PSIRT) portal. The most significant items cover FactoryTalk View SE and Logix controllers.

SD1912: FactoryTalk View SE Privilege Escalation (CVE-2026-39512)

CVSS v3.1 Base Score: 8.8 (High)

FactoryTalk View SE (Site Edition) V13.0 and earlier contain a privilege escalation vulnerability in the authentication handling for FactoryTalk Security. An authenticated user with Operator-level access can escalate privileges to Administrator by manipulating a parameter in the login sequence. FactoryTalk View SE is widely used as the HMI platform for Allen-Bradley and Logix-based automation systems.

Mitigation:

  • Update to FactoryTalk View SE V13.0 CPR 9 SR 15 or later
  • Implement network access controls to restrict FactoryTalk View SE servers to known HMI client IPs

SD1908: Logix 5000 Controllers Denial of Service (CVE-2026-40217)

CVSS v3.1 Base Score: 7.5 (High)

CompactLogix, ControlLogix, and GuardLogix controllers running firmware V35 and earlier are vulnerable to a denial-of-service condition triggered by a malformed EtherNet/IP (CIP) packet. The vulnerability causes the controller to enter a fault state requiring manual recovery. In manufacturing environments, this translates directly to an unplanned production stoppage.

Affected firmware: V35.000 and earlier (multiple Logix 5000 platform variants)

Mitigation:

  • Update to Logix 5000 firmware V36.000 or later (available via Rockwell FactoryTalk Update Manager)
  • Implement CIP traffic filtering to permit EtherNet/IP only from authorised SCADA and HMI systems
  • Deploy Claroty, Dragos, or Nozomi for passive monitoring of CIP traffic anomalies

Additional Rockwell Advisories (Summary)

AdvisoryProductCVSSType
SD1907Arena Simulation7.8Memory corruption in file parser
SD1906FactoryTalk Optix7.5Path traversal in file serving component
SD1905Studio 5000 Logix Designer7.3Unsafe deserialization in add-on profile
SD1904DataMosaix Private Cloud6.9SSRF
SD1903FactoryTalk Analytics6.7Insufficient logging of admin actions
SD1902Kinetix 5700 Servo Drive6.5Cleartext credentials in configuration file
SD1901FactoryTalk Remote Access6.3Missing rate limiting on authentication endpoint
SD1900Plex Industrial IoT5.9Improper certificate validation

Full Rockwell advisories: Rockwell Automation PSIRT portal


Prioritisation for OT Security Teams

Given typical OT patching constraints, prioritise in this order:

Immediate (48-72 hours):

  1. CVE-2026-38944 (TIA Portal): Engineering workstations are often the least-protected assets in OT environments and this is a client-side file-parsing vulnerability — high exploitation likelihood. Apply Update 4/Update 2 now.
  2. CVE-2026-41203 (IGSS): Unauthenticated network-exposed RCE. If patch cannot be applied immediately, implement emergency network controls to block port 12397 from all but authorised IGSS clients.

Within current maintenance window (2-4 weeks): 3. CVE-2026-34711 (SCALANCE W): Authentication bypass on industrial wireless APs — less immediately exploitable if management interfaces are on segmented management VLANs. 4. CVE-2026-39512 (FactoryTalk View SE): Privilege escalation requiring authenticated access — lower urgency if Operator accounts are properly vettted. 5. CVE-2026-40217 (Logix 5000): DoS risk; assess based on criticality of affected production lines.

Next scheduled maintenance cycle: 6-12. Remaining Rockwell and Schneider advisories; prioritise by CVSS score and network exposure of affected systems.

CISA’s advisories are available at cisa.gov/ics-advisories. Siemens advisories at cert-portal.siemens.com. Schneider advisories at se.com/psirt.

Tags
ICS-CERTCISASiemensSchneider ElectricRockwell AutomationTIA PortalIGSSFactoryTalkLogixPatch-TuesdayJuly-2026OT-securitySCADA