CVE-2025-8754Active Exploitation

LOWCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 2 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-26: 3Active Exploitation · 2026-05-26: 2Technical Details · 2026-05-26: 305-26
Signal classification2 categories
Active Exploitation
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: ABB zenon RTS unauth remote-reboot (CVE-2025-8754) hits HMI/SCADA across 8 critical sectors. https://intel.threadlinqs.com/threat/TL-2026-0594 #ThreatIntel #ICS #OTSecurity https://t.co/tpyxKgA6CY

    Post summary

    The alert indicates that CVE-2025-8754 is actively exploited to perform unauthenticated remote reboots on HMI/SCADA systems in eight critical sectors.

    00000185
    51 followersView on X
  • WindowsForum@windowsforum
    General

    🚨 Unauthenticated remote reboot in ABB zenon (CVE-2025-8754) = “nothing burger” until your plant goes dark. Code execution isn’t needed for downtime to become a business incident. #Windows #Security #OT #CVE https://windowsforum.com/threads/cve-2025-8754-abb-zenon-remote-transport-lets-attackers-reboot-targets.419713/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #IndustrialCybersecurity #AbbZenonSecurity https://t.co/0BvxSWQ4cG

    Post summary

    The tweet highlights the ABB zenon remote reboot issue (CVE‑2025‑8754) as a potential cause of business downtime, but provides no PoC, exploit, patch, or verification of active exploitation.

    00000137
    1.1K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploiting CVE-2025-8754 in ABB Ability™ zenon can remotely reboot industrial control systems without authentication. This missing auth flaw enables lateral movement across OT networks, triggering denial of service conditions. Runtime segmentation helps contain such post-compromise activity. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/icsa-26-146-03-cve-2025-8754

    Post summary

    Attackers are actively exploiting CVE-2025-8754 to remotely reboot ABB Ability™ zenon systems without authentication, enabling lateral movement and denial-of-service across OT networks.

    00000144
    1.9K followersView on X

Explore more