Our takeCISA ICSA-26-260-06 warns that ABB Ability Edgenius is affected by the Linux kernel "Copy Fail" vuln (CVE-2026-31431). A locally authenticated user or compromised container can gain root. Update to the fixed version if you run it.Cyber Resilience desk
Sources (4)
- cisa_advisories · cisa_advisories
- cisa_ics · cisa_ics
- auscert_bulletins · auscert_bulletins
- cisa_advisories · cisa_advisories
What this means for you — Security leader:Update ABB Ability Edgenius to the patched version immediately. The Linux kernel CVE-2026-31431 (Copy Fail) lets a local user or compromised container reach root; CISA lists it with active exploitation.
What this means for you — Lean IT orgs:If you run ABB Ability Edgenius, apply the update as soon as you can. It fixes a Linux kernel flaw that lets someone with local access or a hacked container take full control of the system.
What this means for you — MSP:Check every client running ABB Ability Edgenius and push the available update on an emergency schedule. CVE-2026-31431 allows local-to-root escalation from a compromised container; CISA reports active exploitation.
What this means for you — Researcher:CISA ICSA-26-260-06 and the linked CSAF detail the ABB Ability Edgenius exposure to Linux kernel CVE-2026-31431 (Copy Fail). Update the listed versions; Siemens has also released fixes for affected SIPLUS and SIMATIC products.