CodeMeter Runtime vulnerabilities: licensing software is also an attack surface
WIBU-SYSTEMS has released fixes for CodeMeter Runtime, detailed in advisory INCIBE-2026-585. The CodeMeter Runtime vulnerabilities affect a component installed across many industrial and engineering environments without being properly inventoried.

News summary
Advisory INCIBE-2026-585 covers vulnerabilities in CodeMeter Runtime, the license management component from WIBU-SYSTEMS. The manufacturer has released patched versions and the recommendation is to update them.
The significant aspect of this case is where this software resides. CodeMeter is installed alongside engineering, design, industrial control, or calculation applications, often as a silent dependency of the installer. Consequently, it is present on devices that no one has registered as part of a risk chain.
This is the most common pattern we encounter in industry: the inventory includes servers and laptops, but not the third-party components installed with a specific application years ago. When an advisory appears, the organisation does not know how many devices are affected or who is responsible for updating them.
Added to this is a genuine difficulty in production environments: software linked to machinery or production lines cannot always be updated when convenient, as it depends on maintenance windows and sometimes on validation from the equipment manufacturer.
Therefore, a practical approach combines two elements. Firstly, accurately discovering where the component is installed using software inventory tools rather than a spreadsheet. Secondly, if an immediate update is not possible, isolation: segmenting the device, limiting its communication to what is strictly necessary, and monitoring it specifically.
General learning extends beyond this specific vendor. The dependencies that come with other applications —licences, drivers, agents, utilities— form part of the attack surface and should appear in the inventory with the same level of detail as the rest.
Source: WIBU-SYSTEMS / INCIBE — 26 August 2026
Why this matters to a company operating in Spain
The threat landscape affecting Spanish companies no longer distinguishes by size. Attacks are automated, sold as a service, and seek the shortest path: a reused credential, an unpatched server, or a provider with poorly controlled remote access. For an SME, the difference between a minor scare and a multi-day shutdown almost always depends on decisions made before the incident.
That is why every industry update should be read in operational terms: which specific controls would have prevented the problem, what evidence must be preserved, and who makes the decision when the clock is ticking. This is the approach we apply to managed cybersecurity projects at Seintec.
Real business impact
Before deciding on an investment, it is advisable to identify what is at stake. In monitoring of equipment and systems projects, we typically review these four areas with management and the IT manager:
- Operational disruption: orders, invoicing, or production halted while systems are restored.
- Loss or exposure of personal data, with a mandatory 72-hour notification requirement to the AEPD.
- Hidden cost of recovery: overtime, external hiring, and loss of client trust.
- Contractual and compliance requirements (ENS, NIS2, ISO 27001) that demand evidence, not intentions.
Five-step action plan
A useful plan fits on one page. This is the roadmap we apply with our clients to move from news to measurable improvement, without disrupting daily operations:
- Identify through automated software inventory which devices have CodeMeter Runtime installed.
- Cross-reference installed versions with the patched versions published by the manufacturer.
- Prioritise updating office and engineering workstations, where there are no downtime restrictions.
- Isolate and segment production-linked equipment that cannot yet be updated.
- Coordinate an update window with each machine manufacturer and record the scheduled date.
Key indicators you should be measuring
What is not measured is not managed. These indicators allow you to verify if the technological investment is yielding results and serve as the basis for the periodic reports we deliver to our clients:
- Automated software inventory coverage across the entire estate.
- Number of devices with third-party components running vulnerable versions.
- Days of exposure for equipment that cannot be updated immediately.
- Percentage of industrial equipment segmented from the office network.
How we approach it at Seintec: Monitoring of equipment and systems
Proactive supervision of computers, servers and systems to detect issues before they impact your business. We operate from our own datacenter in Spain, with a certified technical team and a single point of contact who knows your infrastructure, so you do not have to explain your environment every time an incident arises.
These are the capabilities we bring to the table in a monitoring of equipment and systems project:
- Performance: Supervision of indicators such as CPU, memory, disk capacity, resource usage, and specific network indicators.
- Hardware health: When device and system allow: S.M.A.R.T. status of disks, capacity and degradation, temperatures, fans, battery status, and other available indicators.
- Services and processes: Monitoring of services and specific processes required for applications and systems to remain operational.
- Operating system: Information regarding device status, operating system, updates, reboots, events, and resources.
- Software: Centralised inventory of applications and versions installed on compatible devices.
- Availability: Monitoring of online/offline status and specific systems, servers, or network devices.
What you gain by working with a technology partner
Outsourcing does not mean losing control: it means gaining predictability, coverage, and independent technical insight. These are the benefits our clients highlight:
- Fewer unexpected incidents: We detect specific signs of degradation before they result in a service interruption.
- Increased availability: We monitor resources, services, and availability to promptly detect anomalous behaviour.
- Extended lifespan and hardware control: The evolution of capacity and specific hardware indicators helps in planning interventions and replacements.
- Updates under control: We can apply patching and update policies in a centralised and planned manner.
Frequently Asked Questions
- How do I know if I have CodeMeter Runtime installed?
- By using a software inventory tool that scans the infrastructure and lists installed components, including those that arrived as a dependency of another application. A manual review is unlikely to detect it in environments with dozens of devices.
- What should be done if a production system cannot be updated?
- Isolate it: segment it into its own network, allow only essential communications, strengthen monitoring over it, and set an update date with the manufacturer. The exposure must be documented and have a fixed deadline.
- How do I know if my company is truly protected?
- With evidence: EDR coverage, two-factor authentication on all remote access, immutable copies, and a recently tested restoration. If any of these four points are not confirmed, there is a real risk of prolonged downtime.
- Where should a company wanting to address monitoring of equipment and systems begin?
- With an audit of the current environment. At Seintec, we perform an initial no-cost review that identifies risks, dependencies, and priorities, resulting in a phased plan with fixed deadlines and budgets.
- Is it necessary to halt business operations during the project?
- No. We plan migrations and changes within agreed windows, with prior pilot tests and rollback options, ensuring disruption is minimal or non-existent for users.
- What type of companies do you serve?
- SMEs and mid-market companies in sectors such as industry, automotive, logistics, retail, legal, and healthcare, with both on-premises and hybrid cloud infrastructure.
- What coverage and response times (SLA) do you offer?
- Support from Monday to Friday, 09:00 to 18:00, and 24x7 emergencies 365 days a year, with a committed response SLA and a 99.98% service SLA in 2025.
Concepts mentioned in this article: Monitoring
You cannot patch what you do not know exists. At Seintec, we monitor devices and systems with continuous software inventory and alerts on vulnerable versions. Request a demonstration.
Contact SeintecRelated service
Monitoring of equipment and systems
Proactive supervision of computers, servers and systems to detect issues before they impact your business.