ICSA-26-132-03
·
Published 2026-05-12
·
View on CISA ICS-CERT ↗
ABB AC500 V3 Multiple Vulnerabilities
CVSS 8.3
HIGH
Risk Summary
ABB became aware of severe vulnerability in the products versions listed as affected in the advisory. An update is available that resolves these vulnerabilities. An attacker who successfully exploited these vulnerabilities could bypass the user management and read visualization files (CVE-2025-2595), read and write certificates and keys (CVE-2025-41659) or cause a denial-of-service (DoS) (CVE-2025-41691).
CVEs (3)
Remediations
- The problem is corrected in the following product versions: - AC500 V3 firmware version 3.9.0 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available from Automation Builder 2.9.0. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download
- Refer to section “General security recommendations” for further advise on how to keep your system secure.
- No workarounds are available
Affected Vendors
ABB
Affected Products (2)
ABB
·
AC500 V3
<3.9.0
ABB
·
AC500 V3
3.9.0
Affected Sectors
Chemical, Critical Manufacturing, Energy, Water and Wastewater
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more