Hitachi Energy RTU500 end-of-life firmware flaws
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Dragos-reported vulnerabilities affect end-of-life Hitachi Energy RTU500 CMU firmware 11.x and prior; no exploitation reported, upgrade recommended.
Hitachi Energy published this advisory via CISA in response to findings from Dragos affecting legacy, end-of-life RTU500 CMU firmware versions (11.x and prior). These older firmware releases were built to the security standards of their era and lack modern security controls such as protocol hardening, stronger authentication, and encrypted communications that have since been added to currently supported RTU500 releases. Six CVEs are associated with this advisory, including three newly assigned 2026 identifiers (CVE-2026-8065, CVE-2026-8067, CVE-2026-8066) and three older, previously known CVEs (CVE-2010-2965, CVE-2014-9195, CVE-2023-46143) likely tied to outdated third-party components bundled in the legacy firmware.
Hitachi Energy confirms currently supported RTU500 firmware is not affected. Since end-of-life versions no longer receive security updates, the vendor strongly recommends upgrading to a supported firmware version rather than attempting to patch. No exploitation in the wild is reported; this is a vulnerability disclosure/EOL notice rather than an active campaign.
Affected organizations are in the energy sector globally, given RTU500 devices are remote terminal units used in substation automation and grid control. CISA and Hitachi Energy recommend standard ICS defense-in-depth: minimizing network exposure, isolating control system networks behind firewalls, avoiding direct internet connectivity, and using VPNs with care for any required remote access, alongside prioritizing migration off end-of-life firmware.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-06
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,850 reports from 149 sources, 467 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs