HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical CVE‑2025‑14771‑14774 in ABB T‑MAC Plus Exposes Manufacturing Controllers

ABB disclosed four CVE‑2025‑14771‑14774 vulnerabilities in its T‑MAC Plus 4.0‑24 controller, each scoring 9.9 CVSS. The flaws could let attackers exfiltrate files or bypass authorization, prompting urgent patching. For SOC 2‑ready firms, the incident underscores the need for continuous vendor‑risk monitoring and audit‑ready remediation evidence.

LiveThreat™ Intelligence · 📅 July 14, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
cisa.gov

Critical CVE‑2025‑14771‑14774 in ABB T‑MAC Plus (Industrial Control System) Threatens Manufacturing Operations

What It Is — ABB disclosed four critical vulnerabilities (CVE‑2025‑14771 to 14774) affecting the T‑MAC Plus 4.0‑24 control‑system firmware. The flaws include file disclosure, authorization bypass, cross‑site scripting, and improper input handling, each rated CVSS v3 9.9.

Exploitability — Public advisory indicates an attacker with network access could craft HTTP requests to exfiltrate files or gain unauthorized control. No public exploit code has been released, but the severity and CVSS score suggest a low barrier for a motivated adversary.

Affected Products — ABB T‑MAC Plus 4.0‑24 (industrial automation controller used in critical manufacturing).

Why It Matters for Compliance & Audit Readiness

  • Vendor‑risk monitoring – SOC 2 requires documented due‑diligence on third‑party hardware; tracking ABB advisories and patch status satisfies CC6.1 (risk mitigation) and CC7.1 (monitoring).
  • Continuous evidence – Capturing remediation timestamps and patch‑level inventory provides audit‑ready evidence of control effectiveness.
  • Control mapping – The vulnerabilities map to SOC 2 security principles (access control, change management, and system operations), so remediation must be reflected in your control matrix.

Recommended Actions

  • Inventory all ABB T‑MAC Plus devices and verify firmware version.
  • Apply ABB’s remediation update immediately; document the patch rollout.
  • Update your vendor‑risk dashboard with the advisory, remediation status, and risk rating.
  • Map the fix to SOC 2 controls (e.g., CC6.1, CC7.1) and retain evidence for the next audit.

Source: CISA Advisory – ICSA‑26‑195‑03

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →