Automation Builder, Drive Application Builder, Virtual Drive, Virtual DrivePlus Impacted by multiple vulnerabilities in Wibu CodeMeter

Plan PatchCVSS 8.63adr011572Sep 3, 2026
ABB
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Multiple vulnerabilities exist in Wibu CodeMeter runtime affecting ABB Automation Builder, Drive Application Builder, Virtual Drive, and Virtual DrivePlus. CVE-2026-81572 allows arbitrary file deletion with system privileges. CVE-2026-81573 permits reading and overwriting CodeMeter Server configuration (Server.ini). CVE-2026-81574 and CVE-2026-81575 cause CodeMeter crashes with information disclosure including process memory and cryptographic canaries. CVE-2026-81576 allows reading sensitive license information. All vulnerabilities are exploitable remotely when CodeMeter network server functionality is enabled, and require no authentication.

What this means
What could happen
An attacker could delete files with system privileges, overwrite license server configuration, crash the CodeMeter licensing service and leak sensitive data from process memory (including cryptographic canaries), or read license information. For ABB automation engineers, this means unauthorized changes to system files, potential service outages for license management, and information disclosure that could aid further attacks.
Who's at risk
ABB automation engineers and control system integrators using Automation Builder, Drive Application Builder, Virtual Drive, or Virtual DrivePlus on Windows workstations or servers. Any organization relying on CodeMeter for license management of these tools should prioritize this update. The vulnerability is most critical for systems where the CodeMeter network server is exposed to untrusted networks.
How it could be exploited
An attacker with network access to a machine running CodeMeter with network server functionality enabled could send crafted requests to the CodeMeter service (default port 22350) to trigger file deletion, configuration overwrites, memory leaks, or denial of service. No authentication is required. The attack surface exists because CodeMeter runtime is installed as a dependency of ABB Automation Builder, Drive Application Builder, Virtual Drive, and Virtual DrivePlus.
Prerequisites
  • Network access to CodeMeter service (typically port 22350)
  • CodeMeter network server functionality must be enabled (IsNetworkServer registry value = 1)
  • Vulnerable CodeMeter runtime version installed (below 8.41a or 9.10)
remotely exploitableno authentication requiredlow complexityhigh CVSS score (8.6)affects multiple ABB engineering tools
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (4)
4 with fix
ProductAffected VersionsFix Status
Automation Builder >2.10.0>2.10.0Fix available
Drive Application Bulder /all/allFix available
Virtual Drive >1.5.1>1.5.11.5.1
Virtual Drive Plus >1.70>1.70Fix available
Remediation & Mitigation
0/4
Do now
0/2
HOTFIXUpdate CodeMeter Runtime to version 8.41a or 9.10 immediately from https://www.wibu.com/support/user/user-software.html
WORKAROUNDDisable CodeMeter network server functionality: open Registry Editor, navigate to HKEY_LOCAL_MACHINE\SOFTWARE\WIBUSYSTEMS\CodeMeter\Server\CurrentVersion\, change IsNetworkServer value from 1 to 0, then restart CodeMeter
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HARDENINGAudit local user accounts on systems running CodeMeter and remove unnecessary accounts to reduce file deletion exposure
Long-term hardening
0/1
HARDENINGRestrict network access to CodeMeter service port (typically 22350) using host-based or network firewalls to trusted engineering networks only
API: /api/v1/advisories/2230a0ed-d616-4d16-a21c-7def32de25f9

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.