PCM600 isn't something you'll find on a typical office PC. It runs on the Windows engineering workstations that utilities and industrial operators use to configure and talk to ABB's Relion protection relays, so it touches energy infrastructure. CISA lists Energy as the critical infrastructure sector and says the product is deployed worldwide. Anyone who manages those Windows boxes should read the advisory.
The headline bug: a SYSTEM service that standard users can edit
CVE-2026-15952 is classified as CWE-732, Incorrect Permission Assignment for Critical Resource. In its CSAF advisory 2NGA003170, ABB says members of the PCMSERVER2014 Users group are given permissions that let them modify a Windows service running under the LocalSystem account. That service is the PCM600 Scheduler Service, a background tool that lets users create and manage scheduled PCM600 tasks.
ABB's FAQ describes how an attack would work. A local user with valid credentials changes the service's configuration so that its executable path points to a malicious command. When the Scheduler service next starts, the command runs as LocalSystem. Windows administrators have seen this many times before: if users can write to a service's configuration, they can make it run whatever they want as SYSTEM.
ABB says a successful attacker could:
- Read or modify PCM600 project data
- Change system configuration and install software
- Disable security controls
- Take complete control of the workstation
ABB's advisory names ABBPCMSchedulerService_v214, the component as it exists in PCM600 2.14. ABB also says the problem isn't specific to that version and applies to the matching component in every other supported PCM600 release. If you run older 2.x builds, assume you are affected.
What an attacker needs
The prerequisites are the main reason this isn't an emergency:
- Local access to the affected workstation
- A valid Windows account in the Local Users group
- No remote route. ABB says the flaw cannot be exploited directly over a network connection.
ABB's CVSS 3.1 vector reflects that: local attack vector, high attack complexity, high privileges required, no user interaction, and high impact on confidentiality, integrity and availability.
What it doesn't do (at least according to the report)
ABB says the finding affects the Windows workstation and that the report did not show any direct impact on connected protection relays or functional-safety functions. ABB also warns that a compromised engineering workstation could be used as a staging point for further unauthorized actions in the operational environment. In OT networks, the engineering workstation is often the most trusted machine, so that warning matters.
Section summary: This is a local privilege escalation on the Windows host running PCM600. It needs an existing account, it isn't remotely exploitable, and ABB hasn't shown any direct effect on relays. It is still a route from "standard user" to "owns the engineering box."
The second bug: path traversal in project archive import
CISA's advisory also covers CVE-2026-15953, a CWE-22 path traversal flaw. According to CISA, the bug is in how PCM600 handles project archive files: insufficient validation of archive entry paths may permit path traversal during extraction, potentially allowing files to be written to locations outside the intended extraction directory. ABB published it separately as advisory 2NGA003179, PCM600 Project Import Path Traversal Vulnerability.
The scoring tells you what kind of attack this is. CISA lists a CVSS 3.1 score of 5.0 with low privileges required and user interaction required, plus a CVSS 4.0 score of 5.6. The integrity impact is high and there's no confidentiality impact. Put plainly, someone has to import a booby-trapped project archive, and the result is files written where they shouldn't be. Nobody is reading your secrets through this bug.
There's a gap in the CISA text. The mitigations listed under CVE-2026-15953 repeat the Scheduler Service workaround word for word, and that workaround does nothing about how archives are extracted. The ABB details specific to the path traversal issue are in 2NGA003179, and I haven't seen that document's remediation section. The general rule ABB applies to all its software-related products still fits here: scan all data imported into your environment before using it. Treat project archives from outside parties the way you'd treat an email attachment from someone you've never met.
PCM600 has had archive handling trouble before. In April 2026, CISA advisory ICSA-26-120-02 covered Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in PCM600 >=1.5|<=2.13. WindowsForum's earlier coverage tied that issue to an old SharpZipLib "Zip Slip" dependency, noting that the upstream vulnerability dates to 2018. The new CVE now includes 2.14 in the affected range. From the evidence I have, I can't tell whether it shares a root cause with the earlier one.
Section summary: CVE-2026-15953 is a medium-severity file-write problem that relies on a user importing a malicious archive. Check ABB advisory 2NGA003179 for its specific guidance, because the CISA mitigation text seems to repeat the Scheduler fix.
How to apply ABB's Scheduler Service workaround
ABB says plainly that this is a workaround, not a fix: it doesn't correct the underlying vulnerability, but it reduces the risk of privilege escalation. The idea is to take SYSTEM out of the picture by running the service as the same account that operates PCM600.
- Open Services.msc.
- Find the ABBPCMSchedulerService instance that matches your installed PCM600 version (for 2.14 it's
ABBPCMSchedulerService_v214). - Open Properties and go to the Log On tab.
- Set the service to log on with the same Windows user account used for the PCM600 application.
- Make sure that account has the "Log on as a service" privilege.
What success looks like: according to ABB, the Scheduler then runs with the configured user's privileges instead of SYSTEM. Someone who tampers with the service's executable path only gains the rights of an account they could probably already reach. That's how the escalation is removed.
Known side effects and failure points
ABB lists several operational effects:
- User rights. Users may need to be granted the "Log on as a service" right. As general Windows background (this is not from ABB): that right is under Local Security Policy, then Local Policies, then User Rights Assignment. In domain environments, Group Policy can overwrite local assignments. If the service stops logging on after a policy refresh, check that first.
- IED authentication. When authentication is enabled for the IED, the Scheduler tool must be used with the same Windows account configured as the service logon account. If those accounts don't match, expect scheduled jobs to fail.
- Account drift. Keeping the PCM600 account and the Scheduler Service account consistent may take ongoing administrative effort. Password rotations and staff changes are the usual causes of breakage.
- Certificate trust. For installations using IED security certificates, ABB says the "Always trust IED security certificates" setting should be enabled only when PCM600-to-IED communication happens in a secure and trusted environment, because it may weaken certificate validation. Don't switch that setting on just to make scheduled jobs work.
One more point from general Windows practice rather than ABB: changing the logon account doesn't change who is allowed to reconfigure the service. The workaround lowers what a hijack of the service can achieve, but it doesn't remove the permission. So restricting membership of the PCMSERVER2014 Users group, and checking that group during access reviews, is still worth doing.
Section summary: Run the Scheduler as the PCM600 operator account, grant "Log on as a service," keep the accounts in sync, and leave certificate trust settings alone unless the network really is trusted.
Is there a patch?
Neither CISA nor ABB's CSAF record for 2NGA003170 names a fixed version. ABB's CSAF labels its remediation a workaround, and third-party CVE trackers for CVE-2026-15953 list the fixed version as Not reported.
ABB's document library does list a PCM600 2.14 Hotfix 2026-09-23 with release note 2NGA003191, posted on September 29, one day after the two advisories. The evidence I've seen doesn't say whether that hotfix addresses either CVE. Read the release note before you assume it does, and ask your local ABB service organization, which is where ABB sends customers for further support.
Scoring: 6.4 or 7.1?
ABB's advisory index lists the Scheduler advisory with a score of 7.1, while ABB's CSAF record gives a CVSS 3.1 base score of 6.4 (Medium). Both numbers are correct. CISA's advisory shows 6.4 under CVSS 3.1 and 7.1 (High) under CVSS 4.0 for the same CVE, so the index is just showing the newer scoring system.
The CSAF vector also contains temporal and environmental metrics: E😛 (proof of concept), RL:W (workaround), and low requirement weightings, which ABB scores at 5.9 temporal and 4.2 environmental. "Proof of concept" is not the same as active exploitation. ABB says it had no reports of exploitation when it issued the advisory, the issue reached it through responsible disclosure, and CISA reports no known public exploitation. Researcher Abhinav Agarwal is credited with reporting the vulnerabilities.
The broader point for OT Windows admins
These bugs aren't new kinds of attack. Writable service configurations and archive extraction that escapes its folder are standard findings in Windows security audits. What raises the stakes is where PCM600 runs. An engineering workstation for protection relays often has access to devices that control the grid.
That makes the usual controls more important:
- Keep PCM600 workstations off general-purpose networks. ABB warns never to connect programming software to any network other than the one for its target devices.
- Control physical and interactive access to these machines, since both CVEs depend on local presence or a user's action.
- Audit service permissions on engineering hosts generally, not only ABB's.
- Scan imported project files before opening them.
Both of these vulnerabilities depend on access the attacker already has, either a local account or a user who opens a malicious archive. The best protection is limiting who can log on to the engineering workstation and what files reach it.
Bottom line: If you run PCM600 2.14 or earlier, apply ABB's Scheduler Service workaround now and test that scheduled jobs still run. Review ABB advisory 2NGA003179 for the archive import flaw, and ask ABB whether the September 2026 hotfix for 2.14 covers either CVE.
References
- ABB Protection and Control IED Manager PCM600 CISA · 2026-10-01T12:00:00+00:00
- ABB PCM600 cisa.gov
- Hol hol.org