ABB AbilityTM zenon Security Risk Due to High-Severity Vulnerabilities in WIBU CodeMeter Runtime
WIBU-Systems CodeMeter Runtime, used within ABB zenon Software Platform for licensing and license server functionality, contains five high-severity vulnerabilities (CVE-2026-81572 through CVE-2026-81576). CVE-2026-81572 allows local privilege escalation and requires local system access and low-privileged user execution. CVE-2026-81573 through CVE-2026-81576 are exploitable only when CodeMeter Runtime is configured as a network server (non-default configuration). Successful exploitation could enable unauthorized access, service disruption, or loss of system integrity on affected zenon installations and license servers.
- Local access to Windows system running ABB zenon with vulnerable CodeMeter Runtime (CVE-2026-81572)
- Network access to CodeMeter Runtime service if configured as network server on port typically used for licensing (CVE-2026-81573 through CVE-2026-81576)
- Low-privileged user account execution capability
Patching may require device reboot — plan for process interruption
/api/v1/advisories/10487634-2a52-4b70-8769-76d04de9386eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.