Bg ShapeBg Shape
THREAT INTELLIGENCE

Multiple Vulnerabilities in Industrial Control Systems - 15th July 2026

Affected Environment
ABB Advant Master Online Builder, ABB Ability Edgenius, ABB T-MAC Plus, and Rockwell Automation 1715-AENTR EtherNet/IP Adapter in ICS and OT environments.

Threat Overview
Multiple CVEs spanning uncontrolled DLL search path (CVSS 4.4), Linux kernel privilege escalation (CVSS 7.8), and critical T-MAC Plus flaws including file disclosure (CVSS 9.9).

Exposure Timeline
Advisories issued 15th July 2026. Patches available from ABB and Rockwell Automation for most affected versions.

Attack Surface
OT and ICS networks with internet-connected or locally accessible ABB and Rockwell components, particularly those permitting removable media or local user access.

Technical Root Cause

Issues include DLL hijacking via uncontrolled search paths, Linux kernel privilege boundary flaw (CVE-2026-31431), broken access controls, stored XSS, and insecure network protocols.

Exploitation Pathway
Local attacker plants malicious DLL or executable; kernel flaw allows container escape to root. T-MAC Plus web flaws allow file exfiltration, admin operations by unprivileged users, and DoS by unauthenticated attackers.

Operational Impact
ICS compromise can disrupt operational technology, trigger equipment failures, or enable unauthorised control of industrial processes.

Strategic Impact
Critical infrastructure and manufacturing environments face elevated risk; a successful attack could cause physical operational impact beyond IT systems.

Required Mitigation
Patch ABB products per advisory guidance. Disable removable media and restrict SSH or Cockpit access on Edgenius. Apply T-MAC Plus update to version 4.0-25.

Incident Response Guidance
Audit local user access on Edgenius and T-MAC Plus. Review ICS network segmentation. Inspect for unauthorised DLL or executable files in search paths on affected ABB systems.

References
CISA ICS Advisories, ABB Security Advisories for Advant Master, Edgenius and T-MAC Plus, CVE-2025-13162, CVE-2026-31431, CVE-2025-14771, CVE-2025-14772, CVE-2025-14773, CVE-2025-14774

Download the Full Report

Explore More of the Latest Threat Intelligence

Trusted by clients worldwide

Logo
Logo
Logo
Logo
Logo
Logo

Your 24/7 Security Partner

Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.

Awards Image
Awards Image
Awards Image
Awards Image
Awards Image
Awards Image