ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact
Siemens, Schneider Electric, and Phoenix Contact issued security bulletins on August 12. CISA published parallel ICS advisories the same day. OT operators should review now.
A control system running the same firmware it shipped with several years ago isn’t a failure state in most OT environments — it’s maintenance policy. That’s the operative context when evaluating who needs to act on August’s ICS Patch Tuesday.
Siemens, Schneider Electric, and Phoenix Contact each released security bulletins on August 12, coinciding with Microsoft’s record-breaking month (421 vulnerabilities, three zero-days). CISA published parallel ICS advisories the same day. SecurityWeek confirmed the releases.
Why the timing matters
The synchronization of ICS vendor patches with Microsoft’s Patch Tuesday cadence is intentional — it gives security teams a single review window each month. What isn’t synchronized: the patch cycle of the plant floor itself. Enterprise IT teams can push a Windows update inside a maintenance window measured in hours. An ICS patch in a running facility may require a planned shutdown, production scheduling approval, and vendor sign-off.
The risk that emerges from August’s volume is queue pressure. When the same cycle produces a 421-vulnerability Microsoft release, three zero-days under active exploitation, and ICS advisories from three major OT vendors, the latter frequently gets deferred to “next quarter.”
What to check
Pull advisories directly from each vendor’s security portal:
- Siemens ProductCERT (cert.siemens.com) — filter by product line and review severity ratings against what you’re running
- Schneider Electric PSIRT — check their security advisory portal for product-family-specific bulletins
- Phoenix Contact PSIRT — advisories listed by product and published date on their security pages
CISA’s ICS advisories page carries vetted summaries for critical-infrastructure operators, with flags for any entries that reach exploited-in-wild or KEV status.
The minimum defensible action: review the advisories for every product line you operate, document what applies, and record whether you’re patching or applying compensating controls. “We assessed and are mitigating via network segmentation” is a defensible position. “We haven’t reviewed it yet” is not.
Review now. Patch when the plant allows it.
Found this useful? Share it.


