VORANT. Threat Intelligence Research Sign in Create a free account

ABB PCM600 flaws enable privilege escalation

routine vulnerability energy

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Two vulnerabilities in ABB PCM600 (≤2.14) allow local privilege escalation and path traversal file writes; no known in-the-wild exploitation.

CISA has published an ICS advisory for ABB's Protection and Control IED Manager PCM600, versions 2.14 and earlier, affecting energy-sector organizations worldwide. Two vulnerabilities were identified: CVE-2026-15952, a privilege escalation flaw in the PCM600 Scheduler Service which runs as LocalSystem while standard users retain permissions via local group membership, allowing a local authenticated attacker to gain control of the host; and CVE-2026-15953, a path traversal vulnerability in PCM600 project archive extraction that could allow files to be written outside the intended directory.

ABB and CISA recommend workarounds rather than a patch at this time: reconfiguring the ABBPCMSchedulerService to run under the same Windows account used for PCM600 (rather than LocalSystem), ensuring the Scheduler tool uses the same account when IED authentication is enabled, and restricting the 'Always trust IED security certificates' setting to trusted environments only. CISA's standard ICS network segmentation and VPN guidance also applies, along with its general anti-phishing recommendations.

No known public exploitation targeting these vulnerabilities has been reported. The flaws require local access and valid credentials, limiting remote risk, but successful exploitation could grant full host control, which is significant in OT/energy environments running protection and control engineering tools. Defenders should apply the vendor-recommended service account reconfiguration and monitor PCM600 hosts for unauthorized local privilege changes or unexpected file writes outside expected archive extraction paths.

Mentioned in this report

Vulnerabilities CVE-2026-15952CVE-2026-15953

Detection guidance

ABB PCM600 Scheduler Service Binary Path Modified via sc.exe

ATT&CK T1543.003

sc.exe reconfiguring the ABBPCMSchedulerService binary path; the service runs as LocalSystem, so this is a privilege escalation primitive (CVE-2026-15952 context). Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: ABB PCM600 Scheduler Service Binary Path Modified via sc.exe
description: Detects sc.exe changing the binPath of ABBPCMSchedulerService. The service
  runs as LocalSystem and standard users may hold rights over it through local group
  membership, so repointing it to another binary yields SYSTEM code execution. The
  vendor workaround changes the service account (obj=), not binPath, so it is not
  matched.
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1543.003
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith: \sc.exe
    CommandLine|contains|all:
    - config
    - ABBPCMSchedulerService
    - binpath
  condition: selection
falsepositives:
- ABB PCM600 upgrade or repair scripts that re-register the service binary path
- Administrators relocating the PCM600 installation
level: high
id: a33aafc7-08a3-565a-af22-6954f01ed4cf
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03

Command Interpreter Spawned by ABB PCM600 Process

ATT&CK T1068

A shell or script host spawned by a PCM600 engineering-tool or scheduler process may indicate exploitation of the tool for local privilege escalation or code execution. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Command Interpreter Spawned by ABB PCM600 Process
description: Detects cmd, PowerShell or script hosts launched by a process whose path
  contains PCM600. PCM600 and its Scheduler Service rarely spawn interactive shells,
  so this may indicate abuse of the LocalSystem scheduler service or archive handling
  flaws. Tune the parent path to the local install location.
tags:
- attack.privilege-escalation
- attack.execution
- attack.t1068
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|contains: PCM600
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
    - \pwsh.exe
    - \wscript.exe
    - \cscript.exe
    - \mshta.exe
  condition: selection
falsepositives:
- PCM600 plug-ins or vendor scripts that legitimately call cmd.exe for configuration
  tasks
- Engineers launching helper tools from within PCM600
level: medium
id: 41f0fa91-fdbf-57ef-887b-bbdcb8764809
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03

ABB PCM600 Process Writing Executable Content to Sensitive System Locations

ATT&CK T1068

A PCM600 process writing executables or scripts to startup, System32 or Tasks locations, consistent with path traversal during project archive extraction (CVE-2026-15953). Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: ABB PCM600 Process Writing Executable Content to Sensitive System Locations
description: Detects a PCM600 process creating executable or script files in Startup
  folders, System32 or the Tasks directory. Normal project archive extraction should
  stay inside the project directory, so such writes suggest path traversal abuse.
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1068
logsource:
  category: file_event
  product: windows
detection:
  selection_proc:
    Image|contains: PCM600
  selection_path:
    TargetFilename|contains:
    - \Start Menu\Programs\Startup\
    - \Windows\System32\
    - \Windows\Tasks\
  selection_ext:
    TargetFilename|endswith:
    - .exe
    - .dll
    - .bat
    - .cmd
    - .ps1
    - .vbs
    - .js
    - .lnk
  condition: selection_proc and selection_path and selection_ext
falsepositives:
- PCM600 installer or update components placing drivers or DLLs in System32
- Engineering workstation imaging or repair operations
level: medium
id: c83968f2-fd0c-53b8-b1f3-6737cf0bfda9
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,566 reports from 152 sources, 502 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs