Executive Summary
In June 2026, ABB disclosed multiple critical vulnerabilities in its T-MAC Plus system, versions 4.0-24, affecting industrial control systems worldwide. The identified vulnerabilities include CVE-2025-14771 (file disclosure), CVE-2025-14772 (authorization bypass), CVE-2025-14773 (stored cross-site scripting), and CVE-2025-14774 (denial-of-service via insecure network protocol). Exploitation of these flaws could lead to unauthorized access, data exfiltration, and disruption of critical manufacturing operations. ABB has released version 4.0-25 to address these issues and recommends immediate updates. (library.e.abb.com)
The disclosure underscores the persistent threat landscape targeting industrial control systems, emphasizing the need for robust cybersecurity measures. Organizations are urged to assess their systems for similar vulnerabilities and implement comprehensive security protocols to safeguard against potential exploits.
Why This Matters Now
The recent vulnerabilities in ABB's T-MAC Plus highlight the increasing risks to industrial control systems, emphasizing the urgency for organizations to update their systems and strengthen cybersecurity defenses to prevent potential exploits and operational disruptions.
Attack Path Analysis
An attacker exploited a file disclosure vulnerability in ABB T-MAC Plus to access sensitive files, then leveraged broken access controls to perform administrative operations, moved laterally within the network, established command and control, exfiltrated data, and caused a denial-of-service attack.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited a file disclosure vulnerability (CVE-2025-14771) in ABB T-MAC Plus to access sensitive files.
Related CVEs
CVE-2025-14771
CVSS 9.9An authenticated user can exfiltrate files containing sensitive information via crafted HTTP GET requests in ABB T-MAC Plus.
Affected Products:
ABB T-MAC Plus – 4.0-24
Exploit Status:
no public exploitCVE-2025-14772
CVSS 8.8Unprivileged users can perform administrative operations due to broken access controls in ABB T-MAC Plus web application.
Affected Products:
ABB T-MAC Plus – 4.0-24
Exploit Status:
no public exploitCVE-2025-14773
CVSS 5.4Authenticated users can execute arbitrary HTML or JavaScript code on victims' browsers due to stored Cross-Site Scripting (XSS) in ABB T-MAC Plus web application.
Affected Products:
ABB T-MAC Plus – 4.0-24
Exploit Status:
no public exploitCVE-2025-14774
CVSS 7.4Unauthenticated attackers can perform a denial-of-service (DoS) attack on the Card Reader service due to insecure network protocol in ABB T-MAC Plus.
Affected Products:
ABB T-MAC Plus – 4.0-24
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Credentials in Files
Valid Accounts
JavaScript
Endpoint Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Oil/Energy/Solar/Greentech
Critical ABB T-MAC Plus vulnerabilities expose terminal management systems handling petroleum, chemical storage with file disclosure, privilege escalation, XSS attacks.
Chemicals
Industrial control system vulnerabilities in ABB T-MAC Plus terminal management allow unauthorized access to chemical terminal operations, product movement controls.
Utilities
Terminal management system flaws enable attackers to compromise critical infrastructure operations through authentication bypass, file exfiltration, and service disruption attacks.
Industrial Automation
ABB T-MAC Plus ICS vulnerabilities create significant risks for automated terminal operations with broken access controls and insecure network protocols.
Sources
- ABB T-MAC Plushttps://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03Verified
- Vulnerabilities in T-MAC Plushttps://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A7840&LanguageCode=en&DocumentPartId=&Action=LaunchVerified
- CVE-2025-14771 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-14771Verified
- CVE-2025-14772 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-14772Verified
- CVE-2025-14773 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-14773Verified
- CVE-2025-14774 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-14774Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Aviatrix Zero Trust CNSF would likely have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial exploitation may still occur, CNSF would likely limit the attacker's ability to leverage the compromised workload to access other systems.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely constrain the attacker's ability to escalate privileges by enforcing strict access controls based on identity and context.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict controls on internal traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely constrain the attacker's ability to establish and maintain command and control channels by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by enforcing strict policies on outbound traffic.
While CNSF focuses on segmentation and access controls, it may indirectly reduce the impact of denial-of-service attacks by limiting the attacker's ability to exploit multiple systems.
Impact at a Glance
Affected Business Functions
- Terminal Operations
- Access Control
- Product Movement Tracking
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive operational data and access credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized administrative operations.
- • Deploy East-West Traffic Security to monitor and control lateral movement within the network.
- • Utilize Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.
- • Ensure regular updates and patches are applied to mitigate known vulnerabilities.



