cvefeed.io Remote Code Execution Vulnerabilities in Accela and ABB Platforms
Article Content
- •CVE-2025-57644 affects Accela Automation Platform, allowing remote code execution.
- •CVE-2024-48851 impacts ABB FLXEON due to improper input validation.
- •Both vulnerabilities require immediate patching and access restrictions.
Two high-severity vulnerabilities have been disclosed affecting the Accela Automation Platform and ABB FLXEON. CVE-2025-57644, published on September 19, 2025, allows authenticated administrative users to execute arbitrary Java code, leading to remote code execution, file write, and server-side request forgery. CVE-2024-48851, published on September 18, 2025, involves improper input validation in ABB FLXEON, enabling remote code execution. Both vulnerabilities pose significant risks, including unauthorized access to sensitive data and potential full server compromise. Users are advised to update to patched versions and restrict administrative access to vulnerable features. No has been reported for either CVE as of now.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2024-48851 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the affected versions?
How urgent is the patching?
What should I do if I can't patch immediately?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…