← All Advisories

CVE-2026-9853

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-9853

Key Details

CVECVE-2026-9853
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-09
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsHitachi Energy microscada_x_sys600 and Hitachi Energy MicroSCADA SYS600
Classified asCWE-303 (Incorrect Implementation of Authentication Algorithm)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Hitachi Energymicroscada_x_sys600
Hitachi EnergyMicroSCADA SYS600
SubsystemsGeneral OT
SectorsMultiple

What to Know

A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself.

Only the SYS600 system users should be permitted to view and modify application objects. (NVD)

What to Do

Monitor Hitachi Energy's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-9853
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-9853
Vendor advisoryhttps://publisher.hitachienergy.com/preview?DocumentID=8DBD000249&LanguageCode=en&DocumentPartId=&Action=Launch