Executive Summary
Industrial technology multinational ABB, in coordination with CISA, has published an urgent cybersecurity advisory detailing a critical vulnerability within the ABB Ability Symphony Plus distributed control system suite. Designated CVE-2026-58902, the vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and affects S+ Operations supervisory control software widely deployed in major electrical generation facilities.
Symphony Plus manages operational control for massive utility assets, including thermal power stations, hydroelectric dam complexes, and combined-cycle plants across more than 40 countries. Exploitation allows an unauthenticated network adversary to execute arbitrary malicious code with SYSTEM privileges on the central SCADA operational server.
Vulnerability Mechanics: .NET BinaryFormatter Deserialization
The flaw is located within the communications listener of the S+ Operations Engineering and Historical Server daemon (SPlusServer.exe), which listens on TCP port 51000 for process graphic updates and client synchronization requests. The service utilized the legacy .NET BinaryFormatter class to unpack incoming object streams without type filtering.
By compiling a serialized object payload utilizing common .NET gadget chains (such as TypeConfuseDelegate or WindowsIdentity), an attacker can transmit an unauthenticated TCP frame that forces the server to execute arbitrary operating system commands during object hydration. Because the service executes under the Windows NT AUTHORITY\SYSTEM account, the attacker achieves complete compromise of the SCADA host.
Exploit Progression Sequence:
1. Attacker establishes raw TCP socket connection to S+ Operations server port 51000
2. Attacker transmits serialized .NET gadget payload containing PowerShell commands
3. SPlusServer.exe deserializes payload via BinaryFormatter without whitelist checks
4. Payload executes within NT AUTHORITY\SYSTEM context on SCADA server
5. Attacker deploys persistent backdoors and acquires full control of plant tags
Operational Impact on Electrical Power Generation
In power utility environments conforming to IEC 62443, the primary SCADA server represents the highest supervisory authority on the operational network. Gaining SYSTEM control of this host allows threat actors to:
- Override automated turbine load-following parameters and generator excitation limits.
- Manipulate operator HMI displays to display normal voltage and temperature readings while actively driving physical plant hardware toward thermal failure.
- Disrupt real-time communication between plant operators and regional electrical grid transmission dispatchers.
Remediation & Mitigation Playbook
ABB has released comprehensive rollup patches and instructs all asset owners to execute the following mitigation sequence immediately:
- Apply Software Rollup: Upgrade affected installations to S+ Operations v3.4 Rollup 2 or apply hotfix HF-58902, which replaces BinaryFormatter with secure JSON/protobuf serialization.
- Block Port 51000 at Firewalls: Restrict TCP port 51000 at all Level 2 and Level 3 internal firewalls, ensuring only authorized engineering stations can communicate with the server.
- Enforce Defense-in-Depth Network Segmentation: Ensure strict physical and logical firewalled separation between enterprise IT networks and the plant operational network in accordance with the Purdue Model.



