Home/Blog/News

Schneider Electric Patches CVSS 9.2 Authentication Bypass in Modicon M580 PLCs

CVE-2026-3869 (CWE-303) allows unauthenticated network access to send arbitrary commands to Modicon M580 and M580 Safety controllers — but most OT environments will not be able to apply the patch immediately.

OT SecuritySeptember 15, 2026Smart Machines & Factories

On September 9, 2026, Schneider Electric disclosed CVE-2026-3869 — a critical authentication algorithm flaw (CWE-303) affecting Modicon M580 and M580 Safety PLCs. The vulnerability carries a CVSS v4.0 score of 9.2 and enables any unauthenticated attacker with network access to send arbitrary commands directly to the controller's application layer, bypassing all authentication controls. The advisory was published as part of the September 2026 ICS Patch Tuesday batch, which also addressed issues in Siemens and AVEVA products.

What the Vulnerability Does

The flaw stems from an incorrect implementation of the authentication algorithm used at the Modicon M580's application communication layer. Under normal operation, clients connecting to the PLC must prove their identity before issuing process commands. CVE-2026-3869 breaks this guarantee: a malformed authentication sequence causes the controller to accept the session as authenticated without verifying credentials. From that point, the attacker has full command authority — they can read and write process data, modify setpoints, start or stop programs, and alter safety function parameters.

Affected versions

  • Modicon M580 CPUs running application firmware below version 4.00;
  • Modicon M580 Safety CPUs running application firmware below version 4.20;
  • Devices reachable over EtherNet/IP or Modbus TCP from an untrusted network.

Schneider Electric confirmed the issue affects devices deployed in energy generation, water treatment, chemical processing, and discrete manufacturing — precisely the sectors where unplanned process changes can cause physical harm or production loss.

Why Patching Will Take Time in Most Plants

The fix is available: upgrading to application firmware 4.00 (M580) or 4.20 (M580 Safety) closes the vulnerability. In an IT environment, deploying a firmware update is a straightforward change-management task. In OT, it is not. Safety-rated PLCs typically require a full validation cycle before any software change is approved for production. This includes functional testing, re-certification of any safety-integrity-level claims, and coordination with process engineers and plant management. At most facilities this takes weeks to months, not hours.

During that window the asset remains exposed. Industry data from Dragos suggests that more than 40% of manufacturing sites running Modicon M580 variants have at least one unit reachable from a corporate IT network without a segmentation boundary. For those assets, the risk is immediate and the timeline to patch is long — a combination that historically precedes exploitation in the wild.

Interim Mitigations

While awaiting a validated firmware update, Schneider Electric and ICS-CERT recommend the following compensating controls:

  1. Network segmentation. Place all Modicon M580 CPUs behind a dedicated OT firewall. Block inbound EtherNet/IP (TCP/UDP 44818) and Modbus TCP (TCP 502) from untrusted network segments. Remote access must route exclusively through a jump server with MFA.
  2. Allowlist communication partners. If your PLC programming software supports source-IP filtering (e.g. via EcoStruxure Control Expert), restrict the list of hosts authorised to open application sessions.
  3. Deploy OT-specific monitoring. Solutions from Dragos, Claroty, or Nozomi Networks passively inspect Modbus and EtherNet/IP traffic and can alert on authentication anomalies and unexpected command sequences — even when the controller itself cannot enforce authentication correctly.
  4. Prioritise safety PLCs for the patch window. M580 Safety CPUs running below 4.20 represent the highest-risk group: a compromised safety function can suppress alarms or unlock machinery interlocks. Coordinate with your safety system integrator to fast-track the validation cycle for these units.

Monitoring OT networks in real time requires tight integration between plant-floor sensors, edge gateways, and enterprise security dashboards. Custom software that bridges industrial protocols (Modbus, OPC UA, EtherNet/IP) with modern alert and asset-management platforms is increasingly part of the IIoT upgrade path for manufacturers. YuSMP Group designs and builds industrial software integrations and mobile monitoring applications for OT environments.

Sources: Schneider Electric Security Notifications; Blastwave ICS Patch Tuesday September 2026; ICS-CERT Advisory ICSA-2026-252-01.

← Back to Blog Smart Machines & Factories