# Hitachi Energy RTU500 end-of-life firmware flaws

Published: 2026-10-06 · Severity: high · Sectors: energy
Canonical: https://vorant.io/reports/d91dbf82-885e-5074-bdb6-bae15a998aca/hitachi-energy-rtu500-end-of-life-firmware-flaws

> Dragos-reported vulnerabilities affect end-of-life Hitachi Energy RTU500 CMU firmware 11.x and prior; no exploitation reported, upgrade recommended.

Hitachi Energy published this advisory via CISA in response to findings from Dragos affecting legacy, end-of-life RTU500 CMU firmware versions (11.x and prior). These older firmware releases were built to the security standards of their era and lack modern security controls such as protocol hardening, stronger authentication, and encrypted communications that have since been added to currently supported RTU500 releases. Six CVEs are associated with this advisory, including three newly assigned 2026 identifiers (CVE-2026-8065, CVE-2026-8067, CVE-2026-8066) and three older, previously known CVEs (CVE-2010-2965, CVE-2014-9195, CVE-2023-46143) likely tied to outdated third-party components bundled in the legacy firmware.

Hitachi Energy confirms currently supported RTU500 firmware is not affected. Since end-of-life versions no longer receive security updates, the vendor strongly recommends upgrading to a supported firmware version rather than attempting to patch. No exploitation in the wild is reported; this is a vulnerability disclosure/EOL notice rather than an active campaign.

Affected organizations are in the energy sector globally, given RTU500 devices are remote terminal units used in substation automation and grid control. CISA and Hitachi Energy recommend standard ICS defense-in-depth: minimizing network exposure, isolating control system networks behind firewalls, avoiding direct internet connectivity, and using VPNs with care for any required remote access, alongside prioritizing migration off end-of-life firmware.

## Mentioned in this report

- Vulnerabilities: CVE-2010-2965, CVE-2014-9195 (weaponized), CVE-2023-46143, CVE-2026-8065, CVE-2026-8066, CVE-2026-8067

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-06

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d91dbf82-885e-5074-bdb6-bae15a998aca/hitachi-energy-rtu500-end-of-life-firmware-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
