Threat reportICS/SCADATL-2026-0594
ABB Ability zenon Remote Transport Service CVE-2025-8754 — Missing Authentication Allows Unauthorized Remote Reboot of OT Systems
ABB Ability zenon Remote Transport Service CVE-2025-8754 (TL-2026-0594), also tracked as ICSA-26-146-03, is a high-severity ICS/SCADA threat scored CVSS 7.5, first published 2026-05-26. It has no confirmed attribution, affects ABB Ability zenon, references 1 CVE (CVE-2025-8754), maps to 10 MITRE ATT&CK techniques (T1007, T1046, T1190), and is covered by 9 detection rules and 14 indicators of compromise.
- CVSS
- 7.5/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-0594
- Threat ID
- TL-2026-0594
- Also known as
- ICSA-26-146-03, ABB 2NGA002743, zenon RTS Reboot Authentication Bypass
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- Status
- ACTIVE
- Category
- ICS_SCADA
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- chemical, communications, critical-manufacturing, dams, energy, healthcare, information-technology, water-wastewater
- Target regions
- Worldwide, North America, Europe, Asia-Pacific, Middle East, South America, Africa
- Detection rules
- 9
- Indicators of compromise
- 14
Malware and tooling in ABB Ability zenon Remote Transport Service CVE-2025-8754
Malware and tooling: zenon Editor / Engineering Studio
How ABB Ability zenon Remote Transport Service CVE-2025-8754 works
A Missing Authentication for Critical Function vulnerability (CWE-306) in the ABB Ability zenon software platform allows an unauthenticated network attacker to invoke the Reboot OS function exposed by the zensyssrv.exe Remote Transport Service. CISA published ICSA-26-146-03 on 2026-05-26 confirming all zenon versions from 7.50 through 14 are affected across eight critical infrastructure sectors. CVSS v3.1 7.5 HIGH (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) / CVSS v4.0 8.7 — availability-only impact with no confidentiality or integrity loss, but trivially weaponizable for industrial denial-of-service.
ABB Ability zenon is a widely-deployed HMI/SCADA software platform used to engineer and operate supervisory control systems in Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, and Water and Wastewater sectors worldwide. The platform's runtime is supported by the zensyssrv.exe Windows service (ABB zenon System Service), which by default is set to start automatically and which exposes the Remote Transport Service (RTS). RTS is intended to permit engineering operations to be performed remotely against a zenon Runtime host, and it nominally requires the operator to configure a password before any RTS function can be invoked.
CVE-2025-8754 is an authentication bypass affecting the Reboot OS command exposed by RTS. The vulnerability allows an attacker who can reach the zensyssrv.exe service over the network to invoke the Reboot OS function without supplying the configured RTS password. The advisory text from ABB PSIRT and CISA's ICSA-26-146-03 (released 2026-05-26) describes the flaw as a Missing Authentication for Critical Function (CWE-306), placing it squarely in the same class as the OPC UA / IEC-104 / Modbus historical patterns where ICS-specific protocol handlers either omit credential checks entirely or fail to enforce them on a privileged subset of operations. The CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H reflects a pure availability impact: no data is exfiltrated and no integrity is modified, but the target Windows host can be forcibly rebooted at will by an unauthenticated attacker on the same network.
In an OT context the operational impact is disproportionately severe. zenon Runtime is frequently deployed on stand-alone industrial PCs that drive HMI screens, historian collectors, batch controllers, and gateway nodes to PLCs over IEC 60870-5-104, OPC UA, S7, Modbus TCP, and proprietary fieldbus protocols. An unscheduled reboot during a production run can: (1) lose the in-memory state of an HMI session and detach operator visibility from the process, (2) drop active OPC UA / S7 subscriptions and force a reconnection storm against downstream PLCs, (3) interrupt batch or recipe execution mid-step, (4) lose unwritten historian buffers that have not yet flushed to the SQL backend, and (5) for systems in N+1 redundancy, trigger a forced failover that itself can cascade if the standby is similarly vulnerable. Repeat invocation produces a sustained denial-of-service that prevents the operator from regaining control. In safety-instrumented environments the loss of HMI visibility can force an operator to invoke a process trip out of an abundance of caution, converting an IT-layer DoS into a real physical-process shutdown.
The exploit primitive is straightforward and is the canonical Tier-1 ICS vulnerability shape: a critical action handler that does not verify the caller's authentication state before executing. The zensyssrv.exe RTS listener accepts a Reboot OS message and reaches the OS-level reboot path (most likely InitiateSystemShutdownEx or ExitWindowsEx with SE_SHUTDOWN_NAME privilege already held by the LocalSystem-account service) without consulting whether the connection has presented the RTS password. Note that the vulnerability is in the authentication state machine of the RTS protocol handler, not in the cryptographic algorithm or password storage — even an unconfigured RTS password is not a precondition for exploitation. No public proof-of-concept code has been released as of the advisory date and ABB PSIRT reported the issue to CISA itself, indicating a coordinated disclosure path; CISA noted that as of publication there is no evidence of in-the-wild exploitation.
The remediation guidance from ABB is mitigation-only at the time of writing: (a) restrict network reachability to zenon hosts using firewalls, ACLs, and OT-segmentation patterns from IEC 62443 / NIST SP 800-82; (b) audit whether RTS is operationally required and, if not, stop and disable zensyssrv.exe; (c) where RTS is required, stop zensyssrv.exe after each authorized engineering session and start it on-demand. The advisory does not list a fixed product version, so defenders should treat all 7.50–14 deployments as vulnerable until ABB publishes a patched build. Defenders should hunt for network reachability of TCP listeners on zenon hosts, unexpected Windows event 6008 (unexpected shutdown) / 1074 (shutdown initiated) clustered around zenon process trees, and abrupt loss of OPC UA / IEC-104 sessions from a zenon runtime to its connected PLCs.
MITRE ATT&CK techniques used in TL-2026-0594
Discovery
T1007 System Service Discovery; T1046 Network Service Discovery
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Impact
T1489 Service Stop; T1499 Endpoint Denial of Service; T1529 System Shutdown/Reboot
Resource Development
Reconnaissance
T1590 Gather Victim Network Information; T1595 Active Scanning
Affected products and versions in ABB Ability zenon Remote Transport Service CVE-2025-8754
- ABB — Ability zenon
Vulnerable versions: 7.50; 7.60; 8.00; 8.10; 8.20; 10; 11; 12; 13; 14 - ABB — zenon Runtime (zensyssrv.exe Remote Transport Service)
Vulnerable versions: >=7.50,<=14
Remediation for ABB Ability zenon Remote Transport Service CVE-2025-8754
Patches
- ABB has not published a fixed product version as of 2026-05-26 (ICSA-26-146-03). Track ABB Cybersecurity Advisory 2NGA002743 for updates.
Immediate actions
- Restrict network reachability to zenon Runtime hosts via OT-segment firewall ACLs — only allow RTS connectivity from named engineering workstations.
- Audit operational need for Remote Transport Service; stop and disable zensyssrv.exe on every zenon host where RTS is not actively required.
- Where RTS is required for periodic engineering, stop zensyssrv.exe after each authorized session and start it on-demand rather than leaving the auto-start default.
- Enable host-based firewall on zenon Runtime PCs to block inbound RTS traffic from any source outside the engineering management VLAN.
- Hunt Windows Event Logs for event 1074 (system shutdown initiated) and 6008 (unexpected shutdown) on zenon hosts since 2025-08-13 (NVD publication).
Workarounds
- Stop and disable the ABB zenon System Service (zensyssrv.exe) on all hosts where Remote Transport functionality is not used.
- Restrict inbound TCP access to zenon Runtime hosts to engineering workstations only via firewall ACLs.
- Stop zensyssrv.exe immediately after each authorized RTS use to minimize exposure window.
Longer-term hardening
- Deploy IEC 62443 zone-and-conduit segmentation between Level 2 (Process Control) and Level 3 (Operations) so that RTS traffic cannot traverse from corporate IT into OT.
- Roll out OT-aware NIDS (Claroty CTD, Dragos Platform, Nozomi Guardian, Tenable.ot) with signatures for zenon RTS protocol anomalies and unexpected reboot commands.
- Implement Windows Event Forwarding from all zenon Runtime hosts into the SIEM, with priority alerting on 1074/6008/41 plus correlated zensyssrv.exe restarts.
- Adopt configuration baseline that disables zensyssrv.exe by default and only enables it via change-managed work orders.
- Coordinate with ABB on patched zenon build availability and schedule maintenance windows for upgrade once the fixed version is released.
CVEs associated with ABB Ability zenon Remote Transport Service CVE-2025-8754
Weaknesses (CWE) in ABB Ability zenon Remote Transport Service CVE-2025-8754
Timeline of ABB Ability zenon Remote Transport Service CVE-2025-8754
- ABB confirms Missing Authentication for Critical Function (CWE-306) in zensyssrv.exe Remote Transport Service across Ability zenon 7.50 through 14; mitigation-only guidance issued (stop zensyssrv.exe / restrict network access).
- CVE-2025-8754 published in the NVD by ABB PSIRT (cybersecurity@ch.abb.com); ABB Cybersecurity Advisory 2NGA002743 released to customers.
- NVD record last-modified; vulnerability status moved to Deferred. No patched version yet listed.
- Threadlinqs Intelligence opens TL-2026-0594 to track CVE-2025-8754 and provide detection/simulation coverage for zenon RTS reboot authentication bypass.
- CISA states no evidence of active in-the-wild exploitation of CVE-2025-8754 at time of advisory publication.
- CISA publishes ICS Advisory ICSA-26-146-03 elevating CVE-2025-8754 to broad public attention; identifies eight critical infrastructure sectors at risk worldwide.
- As of 2026-05-29, CVE-2025-8754 in ABB zenon remains a live, unpatched concern: ABB still lists no fixed version (all 7.50-14 affected), CISA ICSA-26-146-03 (rev through 2026-05-28) gives mitigation-only guidance, and the trivial network-reachable reboot primitive endangers eight CI sectors. CISA reports no in-the-wild exploitation and it is not in KEV, but with zero patch the exposure is unmitigated.
Sources cited for ABB Ability zenon Remote Transport Service CVE-2025-8754
- CISA ICS Advisory ICSA-26-146-03 — ABB AbilityTM Zenon Remote Transport Vulnerability
- ABB PSIRT Cybersecurity Advisory 2NGA002743 — zenon Remote Transport
- NVD CVE-2025-8754 — Missing Authentication for Critical Function in ABB Ability zenon
- CWE-306 — Missing Authentication for Critical Function
- MITRE ATT&CK T1529 — System Shutdown/Reboot
- MITRE ATT&CK for ICS T0816 — Device Restart/Shutdown
- ABB Ability zenon Product Page
- IEC 62443 ICS Security Zone-and-Conduit Reference
Detection coverage for TL-2026-0594
As of 2026-05-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0594 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.