Six Vulnerabilities Discovered in Hitachi Energy RTU500 End-of-Life Firmware
CISA issues advisory on critical flaws affecting legacy CMU firmware versions 11.x and prior
Key Takeaways
- Six vulnerabilities affect Hitachi Energy RTU500 CMU firmware versions 11.x and prior, which are end-of-life and no longer maintained.
- Two flaws (CVE-2026-8065, CVE-2026-8066) carry CVSS scores of 9.1, enabling unauthenticated firmware upload and arbitrary file write/overwrite.
- CVE-2026-8067 allows an authenticated user to trigger device reboots, causing operational disruption.
- Currently supported firmware versions (12.7.8, 13.9.1, or latest) are not affected.
- Hitachi Energy and CISA recommend upgrading to supported firmware and implementing defense-in-depth measures.
Related Security News
Critical Remote Code Execution Vulnerability in Hitachi Energy SOI
Hitachi Energy has disclosed a high-severity Remote Code Execution vulnerability in the Apache ActiveMQ component of its SOI product. The flaw, tracked as CVE-2026-34197, stems from improper control of code generation in the Jolokia JMX-HTTP bridge. An authenticated attacker can exploit the default access policy to execute arbitrary code on the broker's JVM, potentially compromising confidentiality, integrity, and availability. The vulnerability affects SOI versions 2.0.0 through 2.2.0 and has been assigned a CVSS v3 base score of 8.8 (HIGH).



