✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Chemicals
Breach intelligence, attack campaigns, and threat reports targeting the Chemicals sector.
Explore Other Sectors
Chemicals Threat Reports
Critical DoS Vulnerability in ABB B&R Automation Runtime (CVE-2025-3450)
In October 2025, ABB identified a critical vulnerability (CVE-2025-3450) in the System Diagnostics Manager (SDM) component of B&R Automation Runtime versions prior to 6.3 and Q4.93. This flaw allows unauthenticated, network-based attackers to delete data, leading to denial-of-service conditions. The vulnerability stems from improper resource locking within the SDM, potentially causing affected systems to cease operation upon exploitation. ABB has released updates to address this issue and recommends users upgrade to Automation Runtime versions 6.3 or Q4.93 to mitigate the risk. This incident underscores the importance of timely patch management and robust network security practices, especially in critical infrastructure sectors where such vulnerabilities can have significant operational impacts.
2 months ago
Kill Chain
Critical Vulnerability in ABB Ability™ zenon: CVE-2025-8754
In August 2025, a critical vulnerability (CVE-2025-8754) was identified in ABB's Ability™ zenon software, versions 7.50 through 14. This flaw allows unauthenticated remote attackers to access critical functions, potentially leading to denial-of-service conditions in industrial control environments. The vulnerability arises from missing authentication mechanisms in the Remote Transport Service, enabling unauthorized system reboots. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2025-8754&utm_source=openai)) The incident underscores the importance of robust authentication protocols in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize timely vulnerability assessments and implement comprehensive security measures to mitigate potential risks.
2 months ago
Kill Chain
ABB MConfig Vulnerability CVE-2025-9970: Cleartext Storage of Sensitive Information
In October 2025, ABB disclosed a vulnerability (CVE-2025-9970) in its MConfig software versions up to 1.4.9.21, where sensitive information was stored in cleartext within memory. This flaw could allow attackers with local access to extract credentials, potentially compromising system integrity. ABB released version 1.4.9.22 to address this issue. This incident underscores the critical importance of secure memory handling practices in software development, especially for applications managing sensitive data. Organizations are reminded to promptly apply security patches and review software for similar vulnerabilities to prevent unauthorized access.
2 months ago
Kill Chain
ScadaBR 1.2.0 Vulnerabilities: A Wake-Up Call for SCADA Security
In May 2026, multiple critical vulnerabilities were identified in ScadaBR version 1.2.0, an open-source SCADA platform widely used in critical infrastructure sectors. These vulnerabilities include missing authentication for critical functions (CVE-2026-8602), OS command injection (CVE-2026-8603), cross-site request forgery (CVE-2026-8604), and the use of hard-coded credentials (CVE-2026-8605). Exploitation of these flaws could allow unauthenticated attackers to execute arbitrary code, manipulate sensor readings, and gain administrative access to the system, posing significant risks to operational technology environments. ([windowsforum.com](https://windowsforum.com/threads/cisa-warns-scadabr-1-2-0-flaws-enable-unauthenticated-rce-protect-ot-exposure.418951/post-978793?utm_source=openai)) The discovery of these vulnerabilities underscores the ongoing challenges in securing SCADA systems, especially those exposed to the internet or integrated with IT networks. Organizations must reassess their security postures, implement robust access controls, and ensure timely updates to mitigate such risks.
2 months ago
Kill Chain
Critical Vulnerability in Siemens gWAP: CVE-2026-40175
In May 2026, Siemens disclosed a critical vulnerability (CVE-2026-40175) in its gPROMS Web Applications Publisher (gWAP), stemming from the integration of a vulnerable version of the Axios HTTP client library. This flaw allows attackers to exploit prototype pollution in third-party dependencies, potentially leading to remote code execution or full cloud environment compromise. Siemens has released version 3.1.1 to address this issue and strongly recommends users update immediately. This incident underscores the risks associated with third-party software components in supply chains. Organizations must remain vigilant, ensuring all integrated libraries are up-to-date and secure to prevent similar vulnerabilities from being exploited.
2 months ago
Kill Chain
Critical Vulnerabilities Discovered in ABB AC500 V3 PLCs
In February 2026, ABB disclosed multiple vulnerabilities in its AC500 V3 programmable logic controllers (PLCs), specifically affecting firmware versions prior to 3.9.0. The identified vulnerabilities include CVE-2025-2595, which allows unauthenticated remote attackers to bypass user management and access visualization files; CVE-2025-41659, enabling low-privileged remote attackers to read and write certificates and keys via the CODESYS protocol; and CVE-2025-41691, permitting unauthenticated attackers to cause a denial-of-service (DoS) condition through specially crafted communication requests. These vulnerabilities pose significant risks to industrial control systems, potentially leading to unauthorized access, data manipulation, and service disruptions. The relevance of this incident is underscored by the increasing frequency of cyberattacks targeting industrial control systems, highlighting the critical need for robust security measures in operational technology environments. Organizations utilizing ABB's AC500 V3 PLCs are urged to apply the recommended firmware updates promptly to mitigate these vulnerabilities and safeguard their infrastructure against potential exploits.
2 months ago
Kill Chain
Critical Vulnerabilities in ABB WebPro SNMP Card PowerValue Devices: Immediate Action Required
In January 2026, ABB disclosed multiple vulnerabilities in its WebPro SNMP Card PowerValue devices, including CVE-2025-4675, CVE-2025-4676, and CVE-2025-4677. These flaws encompass improper input validation, incorrect authentication algorithm implementation, and insufficient session expiration. Exploitation could allow attackers with adjacent network access to bypass authentication mechanisms, cause denial-of-service conditions, and potentially compromise the confidentiality, integrity, and availability of critical power management systems. ABB has released firmware updates to address these issues and recommends users apply them promptly. The disclosure of these vulnerabilities underscores the ongoing risks associated with industrial control systems and the importance of timely patch management. Organizations relying on ABB's WebPro SNMP Card PowerValue devices should assess their exposure and implement the recommended updates to mitigate potential threats to their operational technology environments.
2 months ago
Kill Chain
Critical Vulnerability in ABB AC500 V3 PLCs: CVE-2025-15467
In March 2026, ABB disclosed a critical vulnerability (CVE-2025-15467) in its AC500 V3 programmable logic controllers (PLCs) running firmware version 3.9.0. The flaw, a stack buffer overflow in the Cryptographic Message Syntax (CMS) parsing module, allows attackers to send specially crafted CMS messages with oversized Initialization Vectors (IVs), leading to potential denial-of-service conditions or remote code execution. This vulnerability affects critical infrastructure sectors globally, including chemical, manufacturing, energy, and water systems. ([library.e.abb.com](https://library.e.abb.com/public/3f2f68976c3c4cc89a5ab895a725244e/3ADR011536%20AC500%20V3%20-%20Stack%20buffer%20overflow%20in%20Cryptographic%20Message%20Syntax.pdf?x-sign=a8r%2F%2FVJ904MPHpN62nDT6cO8nxGbkletTE2yehKQm%2Fyz3hjiFyv3ky484JHLStaP&utm_source=openai)) The incident underscores the persistent risks in industrial control systems (ICS) due to software vulnerabilities. With ICS environments increasingly targeted by cyber threats, timely patching and robust security measures are essential to prevent exploitation and ensure operational continuity.
2 months ago
Kill Chain
Critical Vulnerability in ABB's IEC 61850 Communication Stack (CVE-2025-3756)
In April 2026, ABB disclosed a vulnerability (CVE-2025-3756) in the IEC 61850 communication stack used in its System 800xA and Symphony Plus products. An attacker with access to the IEC 61850 network could exploit this flaw by sending specially crafted packets, causing the PM 877, CI850, and CI868 modules to enter a fault state, or rendering the S+ Operations 61850 connectivity unavailable, leading to a denial-of-service condition. The overall functionality of the S+ Operations node remains unaffected; only the IEC 61850 communication function is impacted. Affected versions include AC800M (System 800xA) from 6.0.0x through 6.2.0006.0, Symphony Plus SD Series versions A_0 through B_0.005, Symphony Plus MR versions 3.10 through 3.52, and S+ Operations versions 2.1 through 3.3. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-3756?utm_source=openai)) This vulnerability underscores the critical importance of securing industrial control systems, especially those utilizing the IEC 61850 protocol. As cyber threats targeting operational technology environments continue to evolve, organizations must prioritize timely patching, network segmentation, and robust access controls to mitigate potential risks.
2 months ago
Kill Chain
Critical Vulnerabilities in ABB Ability Symphony Plus Engineering: Immediate Action Required
In April 2026, ABB disclosed multiple vulnerabilities in its Ability Symphony Plus Engineering software, primarily due to outdated PostgreSQL components. These vulnerabilities, including CVE-2023-5869, CVE-2023-39417, CVE-2024-7348, and CVE-2024-0985, could allow attackers with network access to execute arbitrary code, potentially compromising entire systems. Affected versions range from 2.2 to 2.4 SP2. ABB has released updates to address these issues and recommends immediate application to mitigate risks. This incident underscores the critical importance of timely software updates and robust network security practices in industrial control systems. Organizations must remain vigilant against emerging threats targeting outdated components to ensure operational integrity and security.
2 months ago
Kill Chain
Yokogawa CENTUM VP Hardcoded Password Vulnerability Exposes Industrial Systems
In March 2026, a hardcoded password vulnerability (CVE-2025-7741) was identified in Yokogawa's CENTUM VP distributed control system. This flaw allows attackers with access to the Human Interface Station (HIS) to log in using the 'PROG' user account, potentially modifying system permissions. Affected versions include CENTUM VP R5.01.00 to R5.04.20, R6.01.00 to R6.12.00, and R7.01.00. Exploitation requires prior access to the HIS screen controls, limiting the immediate risk but highlighting significant security concerns in industrial control systems. ([cvedetails.com](https://www.cvedetails.com/cve/CVE-2025-7741/?utm_source=openai)) This incident underscores the critical need for robust authentication mechanisms in industrial environments. The reliance on hardcoded credentials poses substantial risks, especially when combined with potential insider threats or physical access breaches. Organizations must prioritize updating authentication protocols and implementing comprehensive security measures to mitigate such vulnerabilities.
3 months ago
Kill Chain
Schneider Electric's Foxboro DCS Vulnerability Exposes Critical Infrastructure to Cyber Threats
In March 2026, Schneider Electric disclosed a deserialization vulnerability (CVE-2026-1286) in its EcoStruxure Foxboro DCS versions prior to CS8.1. This flaw allows an authenticated administrator to execute arbitrary code by opening a malicious project file, potentially compromising system confidentiality, integrity, and availability. The vulnerability affects critical infrastructure sectors globally, including energy and manufacturing. ([cvedetails.com](https://www.cvedetails.com/cve/CVE-2026-1286/?utm_source=openai)) This incident underscores the persistent risks associated with deserialization vulnerabilities in industrial control systems. Organizations must prioritize timely software updates and implement strict access controls to mitigate such threats effectively.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports