INCIBE flags Proteus and ABB industrial flaws
INCIBE warned about three flaws in Proteus and seven in ABB products, including one critical issue, and urged immediate patching.
INCIBE issued two back-to-back advisories on industrial software and platforms with high-severity flaws. In Proteus 9.1_SP4 from Labcenter, it identified three vulnerabilities that could allow remote code execution and sensitive data disclosure, while in ABB products it reported seven flaws, one of them critical, and urged immediate deployment of the corrected versions.
Labcenter Proteus under alert
INCIBE issued an alert for three high-severity vulnerabilities in Proteus 9.1_SP4, Labcenter's electronic design software. The issues, tracked as CVE-2026-42953, CVE-2026-49033 and CVE-2026-42958, could allow remote code execution and the disclosure of sensitive information, according to the agency's notice.
The advisory places these issues in the industrial control systems category and says that, at the time of publication, no active exploitation had been detected in real-world environments. As a mitigation measure, INCIBE recommended upgrading to version 9.2 SPO.
Seven flaws in ABB products
In a separate advisory, INCIBE reported seven vulnerabilities in ABB industrial products. The most serious is CVE-2026-6900, tied to the LDAP server connector, with the potential to enable man in the middle attacks and lead to information disclosure or identity spoofing.
The agency urged users to apply the vendor's updates immediately. According to the advisory, the vulnerabilities affect APROL in all versions earlier than R 4.4-01P5 and ABB Ability zenon in versions 7.50, 7.60, 8.00, 8.10, 8.20, 11, 12 and 14.
INCIBE also listed the secure zenon builds: 11 build 400376, 12 build 407620 and 14 build 405141. It also said the vendor has already distributed patched versions.
External references to active exploitation
Among the secondary sources available for this report are posts that mention active exploitation, though with different levels of support. EsGeeks posted on Facebook that CISA had allegedly confirmed active exploitation of a critical remote code execution vulnerability in Oracle Identity Manager, identified as CVE-2025-61757, but the post does not link directly to the original advisory or the KEV catalog.
A RedesZone post also circulated on social media, claiming that about 50,000 Cisco ASA and FTD firewalls remain vulnerable to critical flaws that are allegedly being actively exploited, without providing the CVE identifiers or direct links to the advisories.
Another post, this time on Instagram, says CISA had allegedly added a critical SharePoint vulnerability to its Known Exploited Vulnerabilities catalog because of active exploitation and links it to CCN-CERT content, although it does not specify the CVE or provide a direct link to the catalog or advisory. In the material provided, those mentions are not confirmed by the original sources, so they remain secondary references that have not been officially verified.
Sources
- INCIBE alerta de tres vulnerabilidades críticas en Proteus de Labcenter que permiten ejecución remota de código y fuga de informaciónmoncloa.com· Moncloa / INCIBE
- INCIBE alerta de siete vulnerabilidades críticas en productos ABB, una críticamoncloa.com· Moncloa / INCIBE
- CISA alerta explotación activa de una crítica RCE en Oracle Identity Manager (CVE-2025-61757)facebook.com· EsGeeks (vía CISA)
- Ubiquiti anuncia que han solucionado 25 vulnerabilidades, incluye 2 fallos críticos; cerca de 50,000 firewalls Cisco ASA/FTD siguen vulnerables a fallos críticos explotados activamentefacebook.com· RedesZone
- CISA activa alerta por SharePoint, Adobe parcha 7 fallos 10.0 y la IA ...instagram.com· Instagram (menciona CISA y CCN-CERT)



