Which ABB PCM600 versions are affected by the October 1, 2026 CISA advisory?

CISA’s October 1, 2026 ICS advisory identifies ABB Protection and Control IED Manager PCM600 as the affected product.
Affected versions
The affected versions are:
| Product | Affected versions |
|---|---|
| ABB Protection and Control IED Manager PCM600 | PCM600 2.14 and earlier |
If you operate PCM600, the first check is whether your installed version is 2.14 or older.
What CISA says the risk involves
The advisory says exploitation could allow an attacker to raise privileges or overwrite files. It also lists the Energy sector as affected, with deployments worldwide.
One listed issue involves the PCM600 Scheduler Service running as LocalSystem while standard PCM600 users have permissions through the local users group.
What is not included here
The provided context does not include patch instructions, mitigation steps, or version-specific upgrade guidance. Before making operational changes, check the CISA advisory and ABB’s official guidance for current instructions.
What should energy-sector operators check in ABB PCM600 after the CISA advisory?

Energy-sector operators using ABB PCM600 should start with a narrow check: whether their deployment is running PCM600 2.14 or earlier.
Checks to prioritize
Based on the advisory details provided, operators should confirm:
- whether ABB Protection and Control IED Manager PCM600 is deployed
- whether the version is PCM600 2.14 or earlier
- whether the deployment is part of an Energy-sector environment
- whether standard PCM600 users have local users group permissions
- whether the PCM600 Scheduler Service configuration matches the advisory concern
The context says the Scheduler Service issue involves the service running as LocalSystem while standard PCM600 users have permissions through the local users group.
Why those checks matter
CISA said exploitation could let an attacker raise privileges or overwrite files. That makes user permissions and service privilege level central to understanding exposure.
The advisory also says deployments are worldwide, so the issue is not limited to one country or region in the provided summary.
Use the official advisory for next steps
The context does not provide remediation commands, patch versions, or compensating controls. Treat the CISA advisory as the source to review before deciding on changes in an operational environment.
What changes in risk does the PCM600 Scheduler Service vulnerability create for standard users?

The Scheduler Service issue changes the risk around standard PCM600 users because the service runs as LocalSystem while those users have permissions through the local users group.
The risk change in plain terms
LocalSystem is a highly privileged service context. The context says standard PCM600 users have permissions through the local users group, while the PCM600 Scheduler Service runs as LocalSystem.
CISA said exploitation could allow privilege escalation or file overwrite. In practical review terms, that means standard-user access should not be treated as low-impact without checking the advisory details.
What operators should examine
The provided facts point to three areas to review:
| Area | Why it matters |
|---|---|
| PCM600 version | PCM600 2.14 and earlier are affected |
| Scheduler Service | The issue involves LocalSystem execution |
| Standard user permissions | The advisory highlights local users group permissions |
What is not confirmed here
The context does not say which specific actions a standard user could perform, whether exploitation requires local access, or what patch level resolves the issue. Use CISA’s advisory and vendor guidance for those details.
Sources / Learn more
Related reading
- How should Siemens Siveillance Control and Siveillance Control Pro users address CVE-2026-50093?; Which Siveillance Control and Siveillance Control Pro versions are affected by CVE-2026-50093?; How could the Open Interface Services web module vulnerability lead to root-level access?; What changed in the September 22, 2026 CISA advisory for Siemens Siveillance Control?
- How do I update a Eufy Omni C20 or Omni X10 Pro to firmware version 1.6.4 or later?; Which Eufy Omni C20 and Omni X10 Pro firmware versions are affected by the September 24, 2026 CISA advisory?; What should I do if my Eufy Omni C20 or Omni X10 Pro was paired while running firmware before 1.6.4?; What changed in the CISA advisory for Eufy Omni C20 and Omni X10 Pro released on September 24, 2026?
- How do Siemens WTV676 and WTV776 operators check whether their Web Interface version is affected?; What should operators do if a Siemens WTV676 or WTV776 device enters protection mode and Web Access stops working?; Which Siemens WTV676 and WTV776 updates address the CISA denial of service advisory?
- What changed for Andy Green when the Mets removed his interim tag and made him full-time manager?

Leave a Reply