[NEW] [high] Hitachi Energy RTU500: Multiple Vulnerabilities
An attacker can exploit multiple vulnerabilities in Hitachi Energy RTU500 to cause denial-of-service conditions through application crashes, disclose cookies or authentication information to unintended parties, or bypass intended authentication configurations.
CSIRTS triage
- What
- Multiple vulnerabilities in Hitachi Energy RTU500 allow attackers to cause denial of service through crashes, disclose authentication credentials and cookies, and bypass authentication.
- Who is affected
- Industrial control systems using Hitachi Energy RTU500 are affected.
- Urgency
- High severity; critical infrastructure devices are at risk of takeover, credential theft, and operational disruption.
- Action
- Apply Hitachi Energy patches for all eight CVEs (CVE-2026-17539, CVE-2026-11856, CVE-2026-28388, CVE-2026-6276, CVE-2026-6653, CVE-2026-6732, CVE-2026-8927, CVE-2026-8932) and conduct post-patch verification.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch RTU500
Get an email when a new RTU500 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3167
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-175390.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-118560.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-283880.89% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-62760.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-66530.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-67320.63% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-89270.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-89320.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-90791.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-17539 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-11856 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28388 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6276 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6653 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6732 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8927 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8932 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9079 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [mittel] cURL: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] cURL: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] cURL: Mehrere Schwachstellencert-bund
- unknownUSN-8670-3: curl vulnerabilityubuntu
- unknownMultiples vulnérabilités dans les produits VMware (07 septembre 2026)cert-fr-avis
- medium[UPDATE] [mittel] OpenSSL: Mehrere Schwachstellencert-bund
- mediumCVE-2026-17539: RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short in…nvd
- medium[UPDATE] [medium] libxml2: Vulnerability allows denial of servicecert-bund
- high[NEW] [high] Meinberg LANTIME: Multiple vulnerabilitiescert-bund
- unknownUSN-8670-2: curl vulnerabilityubuntu
- unknownUSN-8670-1: curl vulnerabilityubuntu
- unknownUSN-8651-1: curl vulnerabilityubuntu
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] vim: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] ffmpeg: Mehrere Schwachstellen ermöglichen Codeausführung und DoS2026-09-10
- medium[UPDATE] [mittel] Unbound: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] ffmpeg: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] Internet Systems Consortium BIND: Mehrere Schwachstellen2026-09-10