Configure ABBPCMSchedulerService to run under the same Windows account used for PCM600 operation. Ensure the account has the "Log on as a service" privilege. Use the Scheduler tool with the configured account when IED authentication is enabled. Enable "Always trust IED security certificates" only in secure and trusted environments. Refer to ABB security advisories 2NGA003170 and 2NGA003179.
Quick answers
What is CVE-2026-15953?
Configure ABBPCMSchedulerService to run under the same Windows account used for PCM600 operation. Ensure the account has the "Log on as a service" privilege. Use the Scheduler tool with the configured account when IED authentication is enabled. Enable "Always trust IED security certificates" only in secure and trusted environments. Refer to ABB security advisories 2NGA003170 and 2NGA003179.
How severe is CVE-2026-15953?
medium, CVSS 6.4
Is CVE-2026-15953 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-15953 be mitigated?
Configure ABBPCMSchedulerService to run under the same Windows account used for PCM600 operation. Ensure the account has the "Log on as a service" privilege. Use the Scheduler tool with the configured account when IED authentication is enabled. Enable "Always trust IED security certificates" only in secure and trusted environments. Refer to ABB security advisories 2NGA003170 and 2NGA003179.
CVSS
6.4
Vendor
ABB
Published
Oct 2, 2026 · 03:08
Patch
Unknown / not confirmed
Affected products
ABB Protection and Control IED Manager PCM600
Mitigation
Configure ABBPCMSchedulerService to run under the same Windows account used for PCM600 operation. Ensure the account has the "Log on as a service" privilege. Use the Scheduler tool with the configured account when IED authentication is enabled. Enable "Always trust IED security certificates" only in secure and trusted environments. Refer to ABB security advisories 2NGA003170 and 2NGA003179.
CISA has published advisory ICSA-26-274-03 detailing two vulnerabilities in ABB Protection and Control IED Manager PCM600. CVE-2026-15952 is a privilege escalation flaw in the Scheduler Service, and CVE-2026-15953 is a path traversal vulnerability in project archive processing. Both affect versions 2.14 and earlier. Exploitation of CVE-2026-15952 could allow a local attacker with valid credentials to elevate to LocalSystem. CVE-2026-15953 could allow writing files outside the intended extraction directory. ABB has not released a patched version beyond 2.14; mitigations are recommended.