CISA issued advisory ICSA-26-272-02 on 29 September 2026 detailing 10 vulnerabilities across Toptech TMS7 and its TopHAT terminal management systems. The most severe, CVE-2026-71379, scored CVSS 10.0 and allows an unauthenticated attacker to export arbitrary database tables via a file export endpoint. The advisory notes these flaws affect Toptech TMS7 and TopHAT version 7.6.3, with the vendor having released a fix in release 7.8.
Evidence cited includes the CVSS scores and the explicit exploitation risks described by CISA; as of the report, no public exploitation of these flaws had been confirmed.
Notable CVEs highlighted include CVE-2026-71379 (CVSS 10.0, unauthenticated data export), CVE-2026-70356 (CVSS 9.1, file upload leading to possible PHP code execution with high privileges), and five SQL injection flaws around search, audit log, transaction and reports (CVSS 9.0). Additional lower-severity issues include a session fixation bug (CVE-2026-71302, CVSS 7.1) and other script evaluation and XSS concerns.
All ten vulnerabilities are associated with Toptech TMS7 and TopHAT 7.6.3, with claims that none are publicly exploited at present and no public PoC confirmed.
CISA’s recommended response is to upgrade to release 7.8 and to minimise network exposure of control-system devices, behind firewalls or updated VPNs, avoiding internet exposure until patching is complete. The most severe vulnerability can require no credentials to exploit, underscoring the urgency of applying fixes.