CVE-2026-15953

LOWCVSS 5.6 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-10-01); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-10-01: 1Mentions · 2026-10-02: 110-0110-02
Referenced assets1 URL
Full discourse2 posts
  • CyberWorldOps@CyberWorldOps

    CISA warns of 2 flaws in ABB PCM600 ≤2.14 (CVE-2026-15952, CVE-2026-15953) risking Windows privileges and project files. Review ICSA-26-274-03 and patch fast. #ICSsecurity #ABB #Vulnerability https://cyberworldops.eu/en/two-abb-pcm600-weaknesses-put-windows-privileges-and-project-files-at

    0000011
    13 followersView on X
  • NewsTongue@NewsTongueX

    🔴 ABB power-grid software vulnerable to privilege escalation, path traversal ABB Protection and Control IED Manager PCM600 versions 2.14 and earlier contain two vulnerabilities affecting energy infrastructure worldwide. CVE-2026-15952 allows local attackers with valid credentials to escalate privileges via the Scheduler Service running under LocalSystem account. CVE-2026-15953 permits path traversal in project archive extraction, potentially writing files outside intended directories. No public exploitation reported.

    0000031
    951 followersView on X

Explore more