ABB AbilityTM zenon Security Risk Due to High-Severity Vulnerabilities in WIBU CodeMeter Runtime

Plan PatchCVSS 8.62nga003144Sep 9, 2026
ABB
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

WIBU-Systems CodeMeter Runtime, used within ABB zenon Software Platform for licensing and license server functionality, contains five high-severity vulnerabilities (CVE-2026-81572 through CVE-2026-81576). CVE-2026-81572 allows local privilege escalation and requires local system access and low-privileged user execution. CVE-2026-81573 through CVE-2026-81576 are exploitable only when CodeMeter Runtime is configured as a network server (non-default configuration). Successful exploitation could enable unauthorized access, service disruption, or loss of system integrity on affected zenon installations and license servers.

What this means
What could happen
Attackers could gain elevated privileges on Windows systems running ABB zenon with vulnerable WIBU CodeMeter Runtime, or disrupt licensing and operations on systems configured as CodeMeter license servers. This could allow unauthorized access to the control system and modifications to process logic.
Who's at risk
ABB zenon operators and engineers using the software platform for industrial control, SCADA, or process automation should prioritize this. Organizations running CodeMeter license servers are at highest risk. Any water utilities, power plants, or critical infrastructure using zenon for system management are affected.
How it could be exploited
An attacker with local access to a Windows machine running zenon could execute code as a low-privileged user to trigger local privilege escalation (CVE-2026-81572). Alternatively, if CodeMeter Runtime is configured as a network server (non-default), a remote attacker could exploit network-based vulnerabilities (CVE-2026-81573 through CVE-2026-81576) to execute commands and compromise the license server, affecting all connected zenon installations.
Prerequisites
  • Local access to Windows system running ABB zenon with vulnerable CodeMeter Runtime (CVE-2026-81572)
  • Network access to CodeMeter Runtime service if configured as network server on port typically used for licensing (CVE-2026-81573 through CVE-2026-81576)
  • Low-privileged user account execution capability
remotely exploitable (if CodeMeter configured as network server)low complexity exploitationno authentication required for network vulnerabilitieshigh CVSS score (8.6)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (1)
ProductAffected VersionsFix Status
ABB AbilityTM zenon <=14<8.41aNo fix yet
Remediation & Mitigation
0/5
Do now
0/2
WORKAROUNDIsolate CodeMeter license servers from untrusted networks using firewall rules; restrict network access to the licensing service port to only authorized zenon client systems
HARDENINGDisable CodeMeter Runtime network server functionality if not required for your licensing architecture; revert to local-only or direct licensing if feasible
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate WIBU-Systems CodeMeter Runtime to version 8.41a or later on all ABB zenon installations
Long-term hardening
0/2
HARDENINGImplement strict access controls on Windows systems running zenon; restrict local logon privileges and enforce authentication requirements
HARDENINGEnable enhanced monitoring and logging on zenon systems and CodeMeter license servers to detect unusual privilege escalation or service access attempts
API: /api/v1/advisories/10487634-2a52-4b70-8769-76d04de9386e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.