The industrial software shipped with a database that went out of date years ago

CISA published three new industrial control system advisories on 6 August 2026. The first concerns ABB Ability Zenon, where the IIoT services install alongside MongoDB version 4.2, and the advisory lists thirteen vulnerabilities with a highest score of 7.8. The second concerns Johnson Controls TL280, where CVE-2026-27871 covers credentials embedded in the firmware, scored 4.1. The third concerns Medixant RadiAnt DICOM up to and including version 2025.2, where CVE-2026-17264 can be triggered through a crafted DICOM file, scored 4.3. For all three CISA states that no known public exploitation targeting these vulnerabilities has been reported.

What happens technically

The ABB Ability Zenon advisory is the most instructive, and the reason is not its severity. Zenon is used to control and monitor processes, and CISA states that the product is deployed across chemical, communications, critical manufacturing, dams, energy, healthcare, information technology and water and wastewater sectors. The vulnerabilities do not sit in Zenon itself. They sit in MongoDB version 4.2, which ships with the installation when the IIoT services are deployed. Twelve of the thirteen identifiers in the advisory date from 2020 and 2021, and have therefore been publicly known for years. The newest, CVE-2025-14847, covers mismatched length fields in compressed protocol headers, and according to the description may allow an unauthenticated client to read uninitialised heap memory.

This is a dependency issue, not a product issue. A vendor wraps a third party database inside its own installation, and the customer thereby inherits the vendor's maintenance cadence for that component. ABB cannot point to a simple update, and the vendor's guidance presumes that version 4.2 is no longer considered supported. ABB instead recommends two routes. Either the bundled database is replaced manually with a supported and patched version, where the services are genuinely in use, or the IIoT services are uninstalled entirely through the control panel where they are not. The latter is probably the real answer in many plants, because functionality of this kind is often installed without ever being put to use.

The other two advisories are smaller in scope. Johnson Controls TL280 is affected by CVE-2026-27871, covering credentials embedded in the firmware, classified as use of a broken or risky cryptographic algorithm. The score is 4.1 under CVSS 3.1 and 2.1 under version 4.0, and an attack requires both high privileges and high attack complexity. The fix is firmware 5.63. The vulnerability was reported to CISA by VulnCheck. The Medixant RadiAnt DICOM advisory, by contrast, deserves a clarification, because its text is not consistent. CISA's own summary says exploitation could cause the application to crash, while the description of CVE-2026-17264 in the same advisory says a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, and that this may allow an attacker to execute arbitrary code. The score is 4.3 under CVSS 3.1 and 5.3 under 4.0. The vendor states the application is compiled with Control Flow Guard, data execution prevention and address space layout randomisation, and that this significantly reduces practical exploitability. The fix is version 2026.1.

What this means for you if you operate vendor-delivered systems

None of these three is a crisis, and that is worth saying plainly. Taken together they nonetheless say something about where operational technology risk actually arises. Two of the three concern something that was built in once and then forgotten. A database that came with the installation. A set of credentials sitting in the firmware. Such things are not caught by a vulnerability scanner that looks at the product name, because the name you scan for is ABB Ability Zenon and not MongoDB. Berigo has previously covered seven ICS advisories from CISA. We have also written about six steps for isolating critical OT systems. The point keeps repeating. In operational technology it is rarely zero-days that cause the incidents. It is the age of what is already standing there.

The most important thing here, in our view, is not which of the three advisories applies to you. The question is whether you know what is installed at all. A software bill of materials, meaning a list of the components a product actually consists of, is the difference between searching and looking something up. If you have RadiAnt in use, the advisory is a reminder that image viewers are software that processes files from outside, and that DICOM files arrive from many directions. If you have Zenon standing in a plant, the advisory is an occasion to ask the vendor directly which third party components ship with the product, and who carries responsibility for keeping them updated. Under NIS2 article 21 this is supplier security. You can outsource the component, you cannot outsource the responsibility.

Berigo recommends

  • Check whether the IIoT services are genuinely in use in your Zenon installations, and remove them where they are not.
  • Ask vendors for a list of third party components shipping with the product, and get in writing who updates them.
  • Update Johnson Controls TL280 to firmware 5.63, and rotate keys or passwords that may derive from the embedded values.
  • Move Medixant RadiAnt to version 2026.1, and restrict which sources DICOM files may be opened from.
  • Keep control systems separated from the office network, and verify that they are not reachable from the internet.

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch