CVE-2018-1002208Active Exploitation(sharpziplib_project / sharpziplib)

MEDIUMCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch sharpziplib_project sharpziplib systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharpziplib

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-05-27)
  • 7 total mentions across 3 days

Affected systems

Products
sharpziplib

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-04-30: 2Mentions · 2026-05-06: 1Mentions · 2026-05-27: 4Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-05-27: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-04-30: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-27: 404-3005-0605-27
Signal classification4 categories
Active Exploitation
342.9%
Patch
228.6%
Disclosure
114.3%
General
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-302
Active Exploitation1Patch1
2026-05-061
Active Exploitation1
2026-05-274
Active Exploitation1Disclosure1General1Patch1
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    Patch

    Sources CISA Advisory: ABB PCM600 Zip Slip (CVE-2018-1002208) — April 30, 2026 WindowsNews: ABB PCM600 Patch Compatibility Issues — May 1, 2026 ABB PCM600 Protection and Control IED Manager Documentation NIST CVE-2018-1002208 Record Zip Slip Vulnerability Research (Snyk…

    Post summary

    The text references a CISA advisory for the ABB PCM600 Zip Slip vulnerability (CVE‑2018‑1002208) and includes links to patch compatibility reports and documentation, emphasizing vendor advisories and available mitigations.

    10000176
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On April 30, 2026, CISA republished an advisory for CVE-2018-1002208, a Zip Slip vulnerability in ABB's PCM600 software—the trusted tool used by power utilities worldwide to configure and manage intelligent electronic devices (IEDs) in electrical substations and…

    Post summary

    CISA republished its advisory for CVE‑2018‑1002208, identifying it as a Zip Slip vulnerability in ABB PCM600 software.

    10000111
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    TL;DR CISA republished a critical advisory on April 30 for CVE-2018-1002208, a path traversal flaw in ABB's PCM600 (Protection & Control IED Manager) affecting power grid engineering workstations. The eight-year gap between disclosure and republication signals active…

    Post summary

    CISA republished a critical advisory for CVE-2018-1002208, highlighting a path traversal vulnerability in ABB PCM600 that could be actively exploited, but no patch details are provided.

    1000027
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    30, 2026, — The Eight-Year Echo: CISA Republishes ABB PCM600 Zip Slip, Signals Active OT Threat. TL;DR CISA republished a critical advisory on April 30 for CVE-2018-1002208, a path traversal flaw in ABB's PCM600 (Protection & Control IED Manager) affecting power grid…

    Post summary

    CISA republished a critical advisory for a path traversal flaw (CVE‑2018‑1002208) in ABB's PCM600, highlighting a potential active OT threat but providing no PoC, exploit code, patch details, or evidence of active exploitation.

    10000121
    227 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2018-1002208 in Hitachi Energy PCM600 systems use 'Zip-Slip' directory traversal to write arbitrary files, then escalate privileges by modifying critical system components. Runtime segmentation helps contain post-compromise lateral movement across industrial networks. #Vulnerability 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/hitachi-energy-pcm600-vulnerability-cve-2018-1002208

    Post summary

    Analysis shows attackers are actively exploiting CVE‑2018‑1002208 via Zip‑Slip on Hitachi Energy PCM600, escalating privileges; no PoC, patch, or workaround is referenced.

    0000045
    1.9K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2018-1002208 in ABB PCM600 systems can achieve arbitrary code execution through path traversal, then escalate privileges and move laterally across industrial networks. Runtime segmentation helps contain post-compromise activity in critical infrastructure environments. #IndustrialSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/icsa-26-120-02-abb-pcm600-cve-2018-1002208

    Post summary

    The post confirms real‑world exploitation of CVE‑2018‑1002208 in ABB PCM600 systems, enabling arbitrary code execution, privilege escalation, and lateral movement across industrial networks.

    0000019
    1.9K followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 CVE-2018-1002208 in ABB PCM600: just update to 2.14… unless your relay-family patch compatibility says “lol no.” OT security is fun until uptime wins. #Windows #Security https://windowsforum.com/threads/abb-pcm600-zip-slip-flaw-fix-cve-2018-1002208-or-face-ot-patch-compatibility-issues.415937/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #CisaAdvisory #OtCybersecurity #AbbPcm600 #ZipSlipVulnerability https://t.co/RmjP2CEJ75

    Post summary

    The post alerts users of ABB PCM600 to apply update 2.14 to address CVE‑2018‑1002208, a ZipSlip flaw, noting potential patch compatibility concerns.

    0000025
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsharpziplib_projectsharpziplib---

Explore more