CISA published advisory ICSA-26-274-03 on October 1, 2026, disclosing two vulnerabilities in ABB's Protection and Control IED Manager (PCM600), the Windows application engineers use to configure, commission, and maintain protective relays and other intelligent electronic devices (IEDs) across energy-sector substations. Affected versions are 2.14 and earlier.
What the Vulnerabilities Do
Advisory Summary — ICSA-26-274-03
- CVE-2026-15952 (CVSS 6.4) — Privilege Escalation. PCM600 installs a Scheduler Service that runs under the LocalSystem account, while ordinary PCM600 users hold permissions on that service through membership in the local users group. A local attacker with valid, low-privilege credentials can exploit the mismatch to escalate privileges and take control of the host.
- CVE-2026-15953 — Path Traversal. Insufficient validation of archive-entry paths during extraction can let a specially crafted archive write files outside the intended extraction directory.
- Affected product — ABB Protection and Control IED Manager PCM600, versions 2.14 and earlier.
- Sector — Energy, worldwide deployment. CISA reports no known public exploitation at the time of publication.
Why This Matters for Substation and OT Teams
PCM600 is an engineering workstation tool, not a device exposed to the internet — but that is precisely what makes CVE-2026-15952 worth taking seriously. Engineering laptops that run relay-configuration software sit on the same network segment as the IEDs they program, often with far looser access control than the control-room HMI itself. A contractor, a shared commissioning laptop, or a compromised low-privilege account is a realistic path to that workstation, and the Scheduler Service flaw turns "has a PCM600 login" into "has SYSTEM on the box."
From there, an attacker with full control of the engineering workstation inherits whatever trust that machine has with the relays it configures — including, in many substation setups, the ability to push new protection settings. The path-traversal bug (CVE-2026-15953) compounds the risk during routine operations: importing a shared project archive or configuration backup from a colleague or vendor could silently drop a file outside the extraction folder, including into a location that later gets executed.
Neither flaw requires remote network access or sophisticated exploitation — both assume an attacker already has some foothold, which is exactly the scenario utilities' own segmentation and least-privilege policies are meant to prevent. That makes this advisory a useful prompt to re-check who actually has local accounts on engineering workstations, not just who has network access to them.
Recommended Actions
- Reconfigure the Scheduler Service to run under the same restricted Windows account used for PCM600 itself, per ABB's guidance, instead of leaving it on LocalSystem.
- Audit local user and group membership on every workstation running PCM600 — the vulnerability is only exploitable by accounts that already hold local credentials, so trimming that list closes most of the exposure immediately.
- Treat project and configuration archives as untrusted input until ABB ships a patched extraction routine; verify archive contents before import rather than extracting blindly.
- Apply certificate-trust safeguards as recommended in ABB's advisory, and track the vendor's patch release for version 2.14 and earlier.
The underlying pattern — a background service inheriting a broad system account while regular users retain control over it — is a common gap in bespoke industrial tooling, not just vendor software. Teams building custom configuration or commissioning utilities for protection relays and IEDs can avoid it by running every scheduled task under a scoped service account from day one. YuSMP Group audits exactly this class of privilege and service-account misconfiguration in industrial software and infrastructure.
Source: CISA ICS Advisory ICSA-26-274-03 (published Oct 1, 2026).