ClosedMedium impactAI Generated

ABB B&R Automation Studio Multiple Critical SQLite Vulnerabilities (ICSA-26-141-03)

Occurred 7 Oct 2025·Detected 23 May 2026·
Worldwide deployment; vendor headquartered in Switzerland. Affects energy sector industrial control systems globally.3 reportsEnded 29 May 2026
CyberEnergy

CISA has issued an ICS advisory for ABB B&R Automation Studio versions prior to 6.5, identifying 25 CVEs related to an outdated SQLite third-party component. Vulnerabilities include critical-severity issues (CVSS 9.8) enabling remote code execution, unauthorized access, and data exposure. Affected deployments span the global energy sector. A vendor fix is available in version 6.5.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. MEDIUM: Second-pass historical recalibration. This cyber advisory or vulnerability item is relevant to Cyber and technology-dependent Property/Casualty books, but it does not evidence confirmed insured loss, claims activity, ransomware/business interruption, critical infrastructure outage, or quantified market impact sufficient for HIGH.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts