securityonline.info 9 Oct 2026, 16:03 UTC

CISA Urges Patching of Critical Flaws in Energy Sector Software

CISA Urges Patching of Critical Flaws in Energy Sector Software

SIX critical flaws across Grid Protection Alliance’s openPDC and openHistorian threaten energy-sector critical infrastructure. The vendor lists six CVEs affecting these products, with the most severe having a CVSSv3 score of 9.8. OpenPDC versions before 2.9.482 and openHistorian versions before 2.8.585 are vulnerable, and the Docker image for openPDC is reported to contain hard-coded credentials.

At present, there are no publicly confirmed exploitations, but the advisory from CISA warns that successful exploitation could grant an attacker administrative control, arbitrary code execution, access to sensitive operational data, or the ability to map internal networks.

The article emphasises that patching is urgent, and notes the highest-severity vulnerability is CVE-2026-100730 (Deserialization of Untrusted Data), while other notable flaws include CVE-2026-105281 (Missing Authentication for Critical Function) and CVE-2026-101022 (SSRF).

The vulnerabilities and affected versions are: CVE-2026-100730 (Deserialization of Untrusted Data) affecting openHistorian, CVSS 9.8; CVE-2026-105278 (Hard-coded Credentials) and CVE-2026-104629 (Externally-Controlled Input to Select Classes or Code) affecting multiple 2.9.477/2.9.482 and 2.9.482; CVE-2026-105281 (Missing Authentication for Critical Function); CVE-2026-85479 (Missing Authentication for Critical Function); and CVE-2026-101022 (SSRF).

The article states these flaws are unexploited to date, but CISA urges rapid updates. Mitigation advised includes upgrading openPDC to 2.9.482 and openHistorian to 2.8.585, avoiding production use of the Docker images, and applying strong network segmentation to constrain access to control-system networks behind firewalls.

View full article

Article by CyberSIXT