CISA Warns of Flaws in Four Hitachi Energy Products
CISA warned October 6, 2026 of vulnerabilities in four Hitachi Energy products, with no reported exploitation and upgrades recommended.
CISA published four non-conflicting advisories on October 6, 2026, covering separate Hitachi Energy products used in the energy sector. End-of-life RTU500 series CMU firmware 11.x and earlier, based on Dragos findings, has unauthenticated firmware-upload and file-write flaws CVE-2026-8065 and CVE-2026-8066 (both CVSS 9.1), low-privilege reboot issue CVE-2026-8067 (CVSS 6.5), and legacy issues including CVE-2010-2965 (CVSS 9.8) plus CVE-2014-9195 and CVE-2023-46143; supported releases are unaffected, and Hitachi Energy recommends 12.7.8, 13.9.1, or later. Advisory ICSA-26-279-04 says SOI 2.0.0 through 2.2.0 has authenticated ActiveMQ code-injection flaw CVE-2026-34197 (CVSS 8.8, CWE-94), fixed by patch EP2, which upgrades the broker to ActiveMQ 5.19.5 and OpenJDK 11. Asset Suite 9.9.0 and earlier, reported by EDF, exposes unauthenticated servlets via CVE-2026-7395 (CVSS 8.1) and CVE-2026-11796 (CVSS 4.3); Hitachi Energy says to upgrade to 9.9.1 when available and disable the affected servlets. Advisory ICSA-26-279-05 says REB500 8.3.3.1 and earlier can be disrupted by authenticated IEC 61850 parsing bugs CVE-2024-8176 and CVE-2025-59375 (both CVSS 6.5), fixed in 8.3.4.0. Across the advisories, exploitation is not reported.
- On 2026-10-06, CISA issued advisories for four Hitachi Energy energy-sector products: RTU500, SOI, Asset Suite, and REB500.
- End-of-life RTU500 CMU firmware 11.x and earlier is affected by unauthenticated CVE-2026-8065 and CVE-2026-8066 (both CVSS 9.1), CVE-2026-8067 (CVSS 6.5), and legacy CVE-2010-2965 (CVSS 9.8, VxWorks WDB on UDP 17185), plus CVE-2014-9195…
- SOI 2.0.0 through 2.2.0 has authenticated CVE-2026-34197 (CVSS 3.1 8.8, CWE-94) in Apache ActiveMQ (advisory ICSA-26-279-04); patch EP2 upgrades the Core broker to ActiveMQ 5.19.5 and OpenJDK 11.
- Asset Suite 9.9.0 and earlier has unauthenticated CVE-2026-7395 (CVSS 8.1) and CVE-2026-11796 (CVSS 4.3), reported by EDF; Hitachi Energy advises upgrading to 9.9.1 when available and disabling the affected servlets.
- REB500 8.3.3.1 and earlier is affected by libexpat issues CVE-2024-8176 and CVE-2025-59375 (both CVSS 3.1 6.5; the latter in Expat before 2.7.2) in IEC 61850 parsing (advisory ICSA-26-279-05); the fix is version 8.3.4.0.
- CISA reports no exploitation: SSVC lists none for SOI and not observed for REB500, and exploitation is not reported for RTU500 or Asset Suite.
Coverage timelineoldest first · each row is one article
- · 2d agoHitachi Energy RTU500
CISA Advisories· 66
CISA warns end-of-life Hitachi Energy RTU500 firmware has critical unauthenticated flaws, including arbitrary firmware upload.
- · 2d agoHitachi Energy REB500
CISA Advisories· 36
Hitachi Energy REB500 8.3.3.1 and earlier can be crashed via libexpat flaws in IEC 61850 parsing.
- · 2d agoHitachi Energy Asset Suite
CISA Advisories· 55
Hitachi Energy Asset Suite 9.9.0 and earlier expose unauthenticated servlets that can leak data or disrupt availability.
Vulnerabilities in this storyAll →
- published —
- published —
- CVE-2023-461437.5<1%Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all…