CodeMeter Runtime vulnerabilities: licensing software is also an attack surface
WIBU-SYSTEMS has released fixes for CodeMeter Runtime, detailed in advisory INCIBE-2026-585. The CodeMeter Runtime vulnerabilities affect a component installed across many industrial and engineering environments without being properly inventoried.

News summary
Advisory INCIBE-2026-585 covers vulnerabilities in CodeMeter Runtime, the license management component from WIBU-SYSTEMS. The manufacturer has released patched versions and the recommendation is to update them.
The significant aspect of this case is where this software resides. CodeMeter is installed alongside engineering, design, industrial control, or calculation applications, often as a silent dependency of the installer. Consequently, it is present on devices that no one has registered as part of a risk chain.
This is the most common pattern we encounter in industry: the inventory includes servers and laptops, but not the third-party components installed with a specific application years ago. When an advisory appears, the organisation does not know how many devices are affected or who is responsible for updating them.
Added to this is a genuine difficulty in production environments: software linked to machinery or production lines cannot always be updated when convenient, as it depends on maintenance windows and sometimes on validation from the equipment manufacturer.
Therefore, a practical approach combines two elements. Firstly, accurately discovering where the component is installed using software inventory tools rather than a spreadsheet. Secondly, if an immediate update is not possible, isolation: segmenting the device, limiting its communication to what is strictly necessary, and monitoring it specifically.
General learning extends beyond this specific vendor. The dependencies that come with other applications —licences, drivers, agents, utilities— form part of the attack surface and should appear in the inventory with the same level of detail as the rest.
Source: WIBU-SYSTEMS / INCIBE — 26 August 2026
What happened
Advisory INCIBE-2026-585 covers vulnerabilities in CodeMeter Runtime, the licensing management component from WIBU-SYSTEMS. The manufacturer has published fixed versions, and the recommendation is to update to them.
CodeMeter is installed alongside engineering, design, industrial control or calculation applications, often as a silent installer dependency, present on machines nobody has registered as part of a risk chain.
What it teaches a mid-sized business
The most common pattern in industry is that the inventory covers servers and laptops but not third-party components installed with a specific application years ago. When an advisory appears, the organisation doesn't know how many machines are affected or who is responsible for updating them.
Software tied to machines or production lines can't always be updated when convenient, because it depends on shutdown windows and sometimes on the equipment manufacturer's validation.
What to review
A combined approach for hard-to-update third-party components:
- Discover, with software inventory tools, where the component is actually installed.
- Update immediately wherever possible, following the manufacturer's guidance.
- Isolate machines that can't be updated: segmentation and communication limited to the essential.
- Agree an update date with the equipment manufacturer and document the exposure in the meantime.
Frequently Asked Questions
- How do I know if I have CodeMeter Runtime installed?
- With a software inventory tool that scans the fleet and lists installed components, including those that arrived as a dependency of another application.
- What should you do if a production machine can't be updated?
- Isolate it: segment it on its own network, allow only essential communications, strengthen monitoring and agree an update date with the manufacturer.
- Who published the advisory on this vulnerability?
- INCIBE, in advisory INCIBE-2026-585, referring to components from WIBU-SYSTEMS.
Concepts mentioned in this article: Monitoring
You cannot patch what you do not know exists. At Seintec, we monitor devices and systems with continuous software inventory and alerts on vulnerable versions. Request a demonstration.
Contact SeintecRelated service
Monitoring of equipment and systems
Proactive supervision of computers, servers and systems to detect issues before they impact your business.