VORANT. Threat Intelligence Sign in Get the full feed

Yokogawa FAST/TOOLS exposes CI Server config data

medium vulnerability manufacturingenergy

A cleartext transmission flaw in Yokogawa FAST/TOOLS R9.01–R10.04 and CI Server R1.01–R1.04 leaks server configuration data that could enable further attacks against critical manufacturing and energy systems.

CISA has published an advisory for CVE-2026-11833, an information disclosure vulnerability in Yokogawa's FAST/TOOLS and Collaborative Information Server (CI Server) affecting critical manufacturing, energy, and food/agriculture sectors worldwide. The web server returns responses containing CI Server setting information in cleartext, which attackers could leverage for reconnaissance and subsequent attacks. Affected versions include FAST/TOOLS R9.01 through R10.04 and CI Server R1.01 through R1.04.

Yokogawa has released remediation guidance, recommending users update FAST/TOOLS to R10.04 and apply patch software R10.04 SP4, and update CI Server to R1.05. The vulnerability stems from cleartext transmission of sensitive information (CWE-319). No active exploitation has been reported to CISA at the time of advisory publication.

CISA emphasizes standard ICS defensive measures: isolate control systems from the internet, place them behind firewalls separate from business networks, and use secure remote access methods like VPNs. Organizations should consult Yokogawa's security advisory YSAR-26-0004 for detailed implementation guidance.

Mentioned in this report

Vulnerabilities CVE-2026-11833

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free