AVEVA Pipeline Integrity Monitor
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513 (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824) CVSS Vendor Equipment Vulnerabilities v3 8.4 AVEVA AVEVA Pipeline Integrity Monitor Use of Hard-coded Cryptographic Key, Use of a Broken or Risky Cryptographic Algorithm, Missing Authorization, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United Kingdom Vulnerabilities Expand All + CVE-2026-81821 The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information. View CVE Details Affected Products AVEVA Pipeline Integrity Monitor Vendor: AVEVA Product Version: AVEVA Pipeline Integrity Monitor: <=2025_SP1_P1_build_7.1.9580.8513 Product Status: known_affected Remediations Vendor fix AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit: Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files. For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files. Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords. Vendor fix Important: PIMBoards Project Files migration from older ve
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-818210.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-818220.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-818230.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-818240.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-81821 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81822 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81823 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81824 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-81824: The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a…nvd
- mediumCVE-2026-81823: The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read oper…nvd
- highCVE-2026-81822: The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project…nvd
- highCVE-2026-81821: The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project…nvd
More from CISA Cybersecurity Advisories
- criticalmySCADA myPRO Manager2026-09-15
- criticalSiemens Teamcenter2026-09-15
- criticalSiemens Mendix SAML2026-09-15
- criticalWärtsilä FOS-Onboard2026-09-15
- criticalDigital Watchdog VMAX DVR and NVR Product Lineups2026-09-15