CISA alerts critical vulnerabilities in Toptech TMS7 and TopHAT
Operators of Toptech TMS7 and TopHAT version 7.6.3 must address ten CVEs identified by CISA on Sept. 29, 2026.

The Cybersecurity and Infrastructure Security Agency (CISA) issued a CSAF notification on 2026-09-29 identifying ten CVEs that affect Toptech TMS7 and TopHAT version 7.6.3. The notice assigns a CVSS v3 score of 10 and applies to operators of these control-system products, particularly those supporting the energy, chemical and transportation sectors.
The affected CVEs are CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2026-72507, CVE-2026-71302, CVE-2026-69662 and CVE-2026-71189. Vulnerabilities include unrestricted upload of dangerous file types, session fixation, SQL injection, eval injection, cross-site scripting, and exposure of files or directories to external parties. Exploitation could allow an attacker to access critical data or execute arbitrary code on affected systems.
CISA reports no known public exploitation of these vulnerabilities at this time. The agency recommends that organizations minimize network exposure for all control-system devices, locate control-system networks behind firewalls, and isolate them from business networks. When remote access is required, organizations should employ secure methods such as virtual private networks, keeping VPN software up to date, and conduct impact analysis and risk assessments before deploying defensive measures.
Additional mitigation guidance is available on the CISA industrial control systems webpage, including the technical information paper ICS-TIP-12-146-01B. Organizations observing suspicious activity should follow internal procedures and report findings to CISA for tracking and correlation.
The vulnerabilities were reported to Toptech and CISA by Sachin Shetty and Roy Duisters of Shell CyberDefence. The notice is provided subject to CISA's Notification and Privacy & Use policies.
Further reading


