CVE-2026-43500
View CSAF Summary Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy APM Edge Product are affected: APM Edge vers:APM_Edge/<=6.10 (CVE-2026-43284, CVE-2026-43500) CVSS Vendor Equipment Vulnerabilities v3 8.8 Hitachi Energy Hitachi Energy APM Edge Product Write-what-where Condition, Out-of-bounds Write Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-43284 CWE-123: Write-what-where Condition A vulnerability exists in the IPsec ESP subsystem (esp4, esp6) of the Linux kernel used in APM Edge that allows a local unprivileged user to escalate privileges to root. The flaw exists in how the kernel handles memory pages when processing ESP encrypted network packets. An attacker can craft a packet that causes the kernel to decrypt data directly into memory pages it does not own, including the cached copies of privileged operating system binaries. When one of those binaries is executed, the attacker's injected code runs with root privileges. In APM Edge, the vulnerable kernel modules (esp4, esp6) can be loaded by any local user and exploited. View CVE Details Affected Products Hitachi Energy APM Edge Product Vendor: Hitachi Energy Product Version: APM Edge versions 6.10 and prior Product Status: known_affected Remediations Mitigation Disable the esp4 and esp6 modules [2] Relevant CWE: CWE-123 Write-what-where Condition Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVE-2026-43500 CWE-787: Out-of-bounds Write A vulnerability exists in the RxRPC protocol im
CSIRTS triage
- What
- Dirty Frag vulnerabilities including write-what-where and out-of-bounds write conditions impact confidentiality, integrity, and availability.
- Who is affected
- Hitachi Energy APM Edge product version 6.10 and earlier deployments in energy critical infrastructure worldwide.
- Urgency
- Immediate; critical severity with CVSS 8.8 affecting multiple security properties through memory corruption.
- Action
- Update APM Edge to a version above 6.10 per Hitachi Energy mitigation guidance.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-43500
Get an email if CVE-2026-43500 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Exploitation likely imminentEPSS puts this in the most-targeted tier (92.9% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.8% of all EPSS-scored CVEs.
Advisory coverage (11)
- highexploited[UPDATE] [high] Linux Kernel: Multiple vulnerabilitiescert-bund · 2026-08-25
- unknownexploitedOngoing updates on Copy.fail and variantsaws · 2026-08-20
- criticalHitachi Energy APM Edge Productcisa · 2026-08-13
- highexploited[UPDATE] [high] Linux Kernel (Dirty Frag): Multiple vulnerabilities allow gaining administrator rightscert-bund · 2026-08-07
- unknownMultiple vulnerabilities in Red Hat Linux kernel (July 31, 2026)cert-fr-avis · 2026-07-31
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund · 2026-07-28
- unknownUSN-8616-1: Linux kernel (IBM) vulnerabilitiesubuntu · 2026-07-28
- highUSN-8569-1: Linux kernel (HWE) vulnerabilitiesubuntu · 2026-07-20
- unknownexploitedUSN-8528-1: Linux kernel (Xilinx ZynqMP) vulnerabilitiesubuntu · 2026-07-10
- unknownMultiple vulnerabilities in the Ubuntu Linux kernel (June 26, 2026)cert-fr-avis · 2026-06-26
- unknownLinux Kernel vulnerability Dirty Fragfortinet · 2026-06-03
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-43500)