Status: UPDATED | Advisory ID: CVE-2026-9853
| CVE | CVE-2026-9853 |
| CVSS Score / Version | 7.8 (High) / CVSS v3.1 |
| Updated | 2026-09-09 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Hitachi Energy microscada_x_sys600 and Hitachi Energy MicroSCADA SYS600 |
| Classified as | CWE-303 (Incorrect Implementation of Authentication Algorithm) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Hitachi Energy | microscada_x_sys600 | ||
| Hitachi Energy | MicroSCADA SYS600 |
| Subsystems | General OT |
| Sectors | Multiple |
A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself.
Only the SYS600 system users should be permitted to view and modify application objects. (NVD)
Monitor Hitachi Energy's web page for any future patch releases. See vendor advisory link below.