Vendor
ABB vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 32 vulnerabilities in ABB: 1 in the last 7 days and 3 in the last 90 days, 2 of them critical and 1 exploited in the wild. The most recent, CVE-2026-19438, was published on 23 September 2026. 3 technologies have a page of their own.
- Last 7 days
- 1
- Last 90 days
- 3
- Critical, all time
- 2
- Exploited in the wild
- 1
About ABB
Global technology and engineering company that manufactures industrial equipment, power systems, and automation solutions.
ABB technologies
Latest ABB vulnerabilities
- CVE-2026-19438: ABB Mint Workbench I path traversal vulnerabilityhighCVSS 7.5EPSS 0.3%
- CVE-2023-5778: ABB Freelance Controller improper length parameter handlinghighCVSS 7.5EPSS 0.3%
- CVE-2026-12705: ABB KNX Update Tool missing integrity checkmediumCVSS 6.4
- CVE-2025-13162: ABB Control Builder A and 800xA uncontrolled search path elementmediumCVSS 4.4
- CVE-2025-7064: ABB Freelance authentication bypass by primary weaknessmediumCVSS 6.6
- CVE-2025-14774: ABB T-MAC Plus incorrect authorizationhighCVSS 7.4
- CVE-2025-14773: ABB T-MAC Plus cross-site scriptinghighCVSS 8
- CVE-2025-14772: ABB T-MAC Plus authorization bypass via user-controlled keyhighCVSS 8.8
- CVE-2025-14771: ABB T-MAC Plus unauthorized file and directory accesscriticalCVSS 9.9
- CVE-2021-22291: ABB EIBPORT cross-site scripting and session management flawshighCVSS 8
- CVE-2025-7705: ABB Busch-Welcome Door Opener Actuator authentication bypasshighCVSS 6.8
- CVE-2025-11482: ABB PPT30 OS resource exhaustion in OPC-UA ServerhighCVSS 7.5
- CVE-2025-8754: ABB Ability zenon missing authentication in Remote Transport ServicehighCVSS 7.5
- CVE-2025-7745: ABB AC500 V2 buffer over-read in Modbus serverhighCVSS 5.8
- CVE-2024-46461: ABB Ability Camera Connect multiple vulnerabilities in VLC componenthighCVSS 9.8
- CVE-2025-5517: ABB Terra AC heap-based buffer overflow in OCPP message handlinghighCVSS 6.8
- CVE-2025-9970: ABB LVS MConfig cleartext storage of sensitive information in memoryhighCVSS 7.4
- CVE-2023-45229: ABB B&R PCs multiple vulnerabilities in UEFI PXE stackhighCVSS 8.3
- CVE-2025-10504: ABB Terra AC Wallbox multiple buffer overflowshighCVSS 6.1
- CVE-2025-3465: ABB CoreSense HM and M10 path traversalhighCVSS 7.1
- CVE-2024-41975: ABB Automation Builder Gateway insecure default configurationhighCVSS 5.3
- CVE-2025-4675: ABB WebPro SNMP Card PowerValue multiple vulnerabilitieshighCVSS 8.8
- CVE-2025-2595: ABB AC500 V3 Multiple Vulnerabilities in PLC FirmwarehighCVSS 8.3
- CVE-2025-14510: ABB Ability OPTIMAXhighCVSS 8.1
- CVE-2025-10571: ABB Edgenius Management PortalhighCVSS 9.6
Most severe ABB vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-31431: Linux Kernel crypto algif_aead improper memory handlingcriticalexploited in the wildCVSS 7.8EPSS 2.6%
- CVE-2025-14771: ABB T-MAC Plus unauthorized file and directory accesscriticalCVSS 9.9
- CVE-2024-46461: ABB Ability Camera Connect multiple vulnerabilities in VLC componenthighCVSS 9.8
- CVE-2025-10571: ABB Edgenius Management PortalhighCVSS 9.6
- CVE-2025-15467: OpenSSL stack buffer overflow in CMS AEAD parameter parsinghighCVSS 8.8EPSS 2.9%
- CVE-2025-14772: ABB T-MAC Plus authorization bypass via user-controlled keyhighCVSS 8.8
- CVE-2025-4675: ABB WebPro SNMP Card PowerValue multiple vulnerabilitieshighCVSS 8.8
- CVE-2023-5869: ABB Ability Symphony Plus EngineeringhighCVSS 8.8
- CVE-2025-13779: ABB AWIN GW100 and GW120 missing authentication for critical functionhighCVSS 8.3EPSS 0.0%
- CVE-2025-13777: ABB AWIN GW100 and GW120 authentication bypass via capture-replayhighCVSS 8.3EPSS 0.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/abb.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "ABB vulnerabilities", https://junglewise.ai/threats/vendors/abb, 26 September 2026.