Upgrade Hitachi Energy RTU500 CMU firmware to version 12.7.8 or 13.9.1 or latest. Implement defense-in-depth measures and cybersecurity best practices. Refer to CISA ICS Advisory ICSA-26-279-06 for additional mitigation guidance. Restrict network access to RTU500 management interfaces where possible.
Quick answers
What is CVE-2026-8065?
Upgrade Hitachi Energy RTU500 CMU firmware to version 12.7.8 or 13.9.1 or latest. Implement defense-in-depth measures and cybersecurity best practices. Refer to CISA ICS Advisory ICSA-26-279-06 for additional mitigation guidance. Restrict network access to RTU500 management interfaces where possible.
How severe is CVE-2026-8065?
critical, CVSS 9.1
Is CVE-2026-8065 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-8065 be mitigated?
Upgrade Hitachi Energy RTU500 CMU firmware to version 12.7.8 or 13.9.1 or latest. Implement defense-in-depth measures and cybersecurity best practices. Refer to CISA ICS Advisory ICSA-26-279-06 for additional mitigation guidance. Restrict network access to RTU500 management interfaces where possible.
CVSS
9.1
Vendor
Hitachi Energy
Published
Oct 7, 2026 · 01:36
Patch
Unknown / not confirmed
Affected products
RTU500 series CMU Firmware
Mitigation
Upgrade Hitachi Energy RTU500 CMU firmware to version 12.7.8 or 13.9.1 or latest. Implement defense-in-depth measures and cybersecurity best practices. Refer to CISA ICS Advisory ICSA-26-279-06 for additional mitigation guidance. Restrict network access to RTU500 management interfaces where possible.
Hitachi Energy has published a cybersecurity advisory addressing six vulnerabilities in its RTU500 series CMU firmware versions 11.x and prior, identified by Dragos and tracked by CISA. The flaws range from authentication bypass and relative path traversal to improper authorization, with CVSS scores of 9.1. End-of-life versions are no longer maintained, and Hitachi Energy recommends upgrading to currently supported firmware versions 12.7.8 or 13.9.1 or later.