Six Critical Vulnerabilities Discovered in Grid Protection Alliance openPDC and openHistorian
Multiple high-severity flaws including deserialization and authentication bypass affect energy sector critical infrastructure worldwide
Key Takeaways
- Six CVEs disclosed in Grid Protection Alliance openPDC and openHistorian, with CVSS v3.1 scores up to 9.8.
- CVE-2026-100730 allows unauthenticated deserialization and potential remote code execution on systems without Windows Authentication.
- CVE-2026-105281 permits unauthenticated retrieval of full device and measurement topology via the openPDC data publisher.
- Patches released in openPDC 2.9.482 and openHistorian 2.8.585; Docker image users have no fix planned.
- Operators should verify interface bindings and update to patched versions immediately.
Related Security News

Cisco Advisories Five Critical Vulnerabilities in NX-OS Nexus Switches
Cisco has released security advisories addressing five critical vulnerabilities in the NX-OS operating system used by Nexus data center switches. The flaws could be exploited to execute arbitrary code with root privileges, potentially leading to full device compromise and lateral movement within data center environments.

