CiberLATAMbywhalemate

INCIBE flags Proteus and ABB industrial flaws

INCIBE warned about three flaws in Proteus and seven in ABB products, including one critical issue, and urged immediate patching.

Whalemate Labs · AI-assisted researchJul 9, 20262 min read

INCIBE issued two back-to-back advisories on industrial software and platforms with high-severity flaws. In Proteus 9.1_SP4 from Labcenter, it identified three vulnerabilities that could allow remote code execution and sensitive data disclosure, while in ABB products it reported seven flaws, one of them critical, and urged immediate deployment of the corrected versions.

Labcenter Proteus under alert

INCIBE issued an alert for three high-severity vulnerabilities in Proteus 9.1_SP4, Labcenter's electronic design software. The issues, tracked as CVE-2026-42953, CVE-2026-49033 and CVE-2026-42958, could allow remote code execution and the disclosure of sensitive information, according to the agency's notice.

The advisory places these issues in the industrial control systems category and says that, at the time of publication, no active exploitation had been detected in real-world environments. As a mitigation measure, INCIBE recommended upgrading to version 9.2 SPO.

Seven flaws in ABB products

In a separate advisory, INCIBE reported seven vulnerabilities in ABB industrial products. The most serious is CVE-2026-6900, tied to the LDAP server connector, with the potential to enable man in the middle attacks and lead to information disclosure or identity spoofing.

The agency urged users to apply the vendor's updates immediately. According to the advisory, the vulnerabilities affect APROL in all versions earlier than R 4.4-01P5 and ABB Ability zenon in versions 7.50, 7.60, 8.00, 8.10, 8.20, 11, 12 and 14.

INCIBE also listed the secure zenon builds: 11 build 400376, 12 build 407620 and 14 build 405141. It also said the vendor has already distributed patched versions.

External references to active exploitation

Among the secondary sources available for this report are posts that mention active exploitation, though with different levels of support. EsGeeks posted on Facebook that CISA had allegedly confirmed active exploitation of a critical remote code execution vulnerability in Oracle Identity Manager, identified as CVE-2025-61757, but the post does not link directly to the original advisory or the KEV catalog.

A RedesZone post also circulated on social media, claiming that about 50,000 Cisco ASA and FTD firewalls remain vulnerable to critical flaws that are allegedly being actively exploited, without providing the CVE identifiers or direct links to the advisories.

Another post, this time on Instagram, says CISA had allegedly added a critical SharePoint vulnerability to its Known Exploited Vulnerabilities catalog because of active exploitation and links it to CCN-CERT content, although it does not specify the CVE or provide a direct link to the catalog or advisory. In the material provided, those mentions are not confirmed by the original sources, so they remain secondary references that have not been officially verified.

Sources

View all