ABB has disclosed a critical security vulnerability affecting its Ability OPTIMAX energy management platform. The flaw allows attackers to bypass authentication mechanisms when OPTIMAX is integrated with Microsoft Azure Active Directory for Single Sign-On (SSO). By exploiting this weakness, a remote attacker could gain unauthorized administrative access to the system, effectively taking full control of the OPTIMAX environment. Given the platform’s role in managing and optimizing industrial energy operations, successful exploitation could lead to severe operational, financial, and safety impacts. The vulnerability is caused by an incorrect implementation of the authentication logic within OPTIMAX’s Azure AD SSO integration. During the authentication flow, insufficient validation of identity assertions allows an attacker to impersonate a legitimate user without possessing valid credentials. This flaw breaks a core trust boundary in the authentication process, enabling unauthorized access over the network. Once exploited, the attacker inherits the privileges of the impersonated account, which may include administrative-level permissions. With this access, malicious actors can modify system configurations, disrupt energy optimization workflows, disable services, or introduce malicious code into the OPTIMAX environment. In industrial and critical infrastructure contexts, such actions could lead to downtime, loss of operational visibility, or manipulation of energy usage data. The issue affects multiple OPTIMAX versions across the 6.x release line prior to patched builds. Because the attack does not require prior authentication and can be executed remotely, the risk is elevated for deployments exposed to untrusted networks or lacking strict access controls. ABB has classified the vulnerability as critical due to the ease of exploitation and the potential for complete system compromise. Organizations using ABB Ability OPTIMAX are strongly advised to apply the latest security updates immediately. Where patching is not yet feasible, disabling Azure AD SSO and restricting network access can help reduce exposure until permanent remediation is completed.
Researchers have identified Android.MagicAd, an advanced Android trojan family designed to bypass platform protections and deliver intrusive advertisements from the background. The...
A critical security vulnerability identified as CVE 2026 44963 has been discovered in Veeam Backup and Replication, a widely used enterprise backup and recovery solution. The vulne...
Apple has announced a new security feature that automatically updates weak, reused, or compromised passwords using Apple Intelligence. Unveiled during WWDC 2026, the capability enh...