← All Advisories

CVE-2026-8065

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-8065

Key Details

CVECVE-2026-8065
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-09-29
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high.
Affected productsHitachi Energy RTU500 series CMU firmware
Classified asCWE-306 (Missing Authentication for Critical Function)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Hitachi EnergyRTU500 series CMU firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device. (NVD)

What to Do

Monitor Hitachi Energy's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-8065
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-8065