Yokogawa FAST/TOOLS exposes CI Server config data
A cleartext transmission flaw in Yokogawa FAST/TOOLS R9.01–R10.04 and CI Server R1.01–R1.04 leaks server configuration data that could enable further attacks against critical manufacturing and energy systems.
CISA has published an advisory for CVE-2026-11833, an information disclosure vulnerability in Yokogawa's FAST/TOOLS and Collaborative Information Server (CI Server) affecting critical manufacturing, energy, and food/agriculture sectors worldwide. The web server returns responses containing CI Server setting information in cleartext, which attackers could leverage for reconnaissance and subsequent attacks. Affected versions include FAST/TOOLS R9.01 through R10.04 and CI Server R1.01 through R1.04.
Yokogawa has released remediation guidance, recommending users update FAST/TOOLS to R10.04 and apply patch software R10.04 SP4, and update CI Server to R1.05. The vulnerability stems from cleartext transmission of sensitive information (CWE-319). No active exploitation has been reported to CISA at the time of advisory publication.
CISA emphasizes standard ICS defensive measures: isolate control systems from the internet, place them behind firewalls separate from business networks, and use secure remote access methods like VPNs. Organizations should consult Yokogawa's security advisory YSAR-26-0004 for detailed implementation guidance.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-01
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free