Critical Vulnerabilities in AVEVA Industrial Systems: What You Need to Know and How to Stay Protected

Introduction

The security of industrial systems is an increasingly central topic in today’s digital landscape. On March 4, 2026, the American Cybersecurity and Infrastructure Security Agency (CISA) published an official advisory regarding several vulnerabilities discovered in products by AVEVA, a company specializing in software for the control and management of industrial facilities. As of now, no cases of active exploitation of these vulnerabilities have been reported, but their severity makes it appropriate to inform the affected organizations.

What Happened

Researchers identified three vulnerabilities in AVEVA System Platform, OMI Server, and Historian products — tools used by industrial companies to monitor and manage complex production processes. The three vulnerabilities, identified by the codes CVE-2026-0623, CVE-2026-0624, and CVE-2026-0625, relate respectively to the insecure handling of externally sourced data, the potential exposure of sensitive information, and a flaw in the access path control for system files. In simple terms, these flaws could allow a malicious actor to remotely take control of a system, temporarily render it inoperable, or access information that should remain confidential.

The first of the three vulnerabilities received a severity score of 9.8 out of 10, classified as critical. The other two received a score of 7.5 out of 10, considered high. These values are assigned following an international standard and help organizations determine how urgently they need to act.

Why It Matters and What the Potential Impact Is

The affected products are used in strategic sectors such as energy production, water management, manufacturing, and other areas critical to everyday life. A potential attack exploiting these vulnerabilities could cause operational disruptions, loss of sensitive data, or, in the most severe cases, compromise the safety of industrial facilities. It is important to emphasize that, at the time the advisory was published, no real-world attacks exploiting these weaknesses had been reported.

What Organizations and Users Can Do Now

AVEVA has already published its own security advisory with specific guidance for customers. Organizations using the affected products should promptly consult the vendor’s official website to check whether updates or corrective patches are available. It is also advisable to review the network configurations of the facilities, limiting access to authorized users and systems only. Those managing critical infrastructures can refer to CISA’s guidance for a more in-depth risk assessment.

Final Takeaways

  • Three high and critical severity vulnerabilities were identified in AVEVA industrial software and publicly disclosed on March 4, 2026.
  • No cases of active exploitation have been reported to date, but acting promptly to apply updates remains the most prudent course of action.
  • Organizations operating in critical sectors should consult the official advisories from CISA and AVEVA for up-to-date and specific instructions.

Sources:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-062-03
https://nvd.nist.gov/vuln/detail/CVE-2026-0623
https://www.aveva.com/en/about/news/press-releases/2026/aveva-security-advisory-2026-062

Source: CISA Advisories