← Back to home
ICSA-26-132-03  ·  Published 2026-05-12  ·  View on CISA ICS-CERT ↗

ABB AC500 V3 Multiple Vulnerabilities

CVSS 8.3 HIGH

Risk Summary

ABB became aware of severe vulnerability in the products versions listed as affected in the advisory. An update is available that resolves these vulnerabilities. An attacker who successfully exploited these vulnerabilities could bypass the user management and read visualization files (CVE-2025-2595), read and write certificates and keys (CVE-2025-41659) or cause a denial-of-service (DoS) (CVE-2025-41691).

Remediations

  • The problem is corrected in the following product versions: - AC500 V3 firmware version 3.9.0 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available from Automation Builder 2.9.0. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download
  • Refer to section “General security recommendations” for further advise on how to keep your system secure.
  • No workarounds are available

Affected Vendors

ABB

Affected Products (2)

ABB · AC500 V3 <3.9.0
ABB · AC500 V3 3.9.0

Affected Sectors

Chemical, Critical Manufacturing, Energy, Water and Wastewater

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more