Skip to content
Remote Code Execution Vulnerabilities in Accela and ABB Platforms

Remote Code Execution Vulnerabilities in Accela and ABB Platforms

First seen 5 Oct 2026, 00:02 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 00:02 UTC

Two high-severity vulnerabilities have been disclosed affecting the Accela Automation Platform and ABB FLXEON. CVE-2025-57644, published on September 19, 2025, allows authenticated administrative users to execute arbitrary Java code, leading to remote code execution, file write, and server-side request forgery. CVE-2024-48851, published on September 18, 2025, involves improper input validation in ABB FLXEON, enabling remote code execution. Both vulnerabilities pose significant risks, including unauthorized access to sensitive data and potential full server compromise. Users are advised to update to patched versions and restrict administrative access to vulnerable features. No has been reported for either CVE as of now.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2025-09-18
CVE-2024-48851 published
ABB disclosed a remote code execution vulnerability in FLXEON affecting versions through 9.3.5.
cvefeed.io
2025-09-19
CVE-2025-57644 published
Accela disclosed multiple vulnerabilities in the Automation Platform Test Script feature, allowing remote code execution.
cvefeed.io

More articles in this cluster (2)

Following this threat?

Track CVE-2024-48851 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the affected versions?
CVE-2025-57644 affects Accela Automation Platform 22.2.3.0.230103, while CVE-2024-48851 affects ABB FLXEON through version 9.3.5.
How urgent is the patching?
Patching is urgent due to the critical nature of CVE-2025-57644, which has a CVSS score of 9.1.
What should I do if I can't patch immediately?
Restrict administrative access to the affected features and review system logs for suspicious activity.