Toptech TMS7/TopHAT fuel systems get 10 CVEs patched
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CISA discloses 10 vulnerabilities in Toptech TMS7 and TopHAT fuel management systems, including unauthenticated data export, RCE via file upload, and multiple SQL injections; fixed in v7.8.
CISA published an ICS advisory covering ten vulnerabilities in Toptech Systems' TMS7 and TopHAT fuel/tank management software (version 7.6.3), used across energy, chemical, and transportation sector organizations worldwide. The most severe issue (CVE-2026-71379) allows any unauthenticated attacker to export arbitrary database tables via a crafted POST request to the file export endpoint. A second critical flaw (CVE-2026-70356) lets an attacker bypass server-side file type restrictions on the TMS file upload endpoint to upload and execute arbitrary PHP files, achieving remote code execution on the web server.
The advisory also lists five separate time-based blind SQL injection vulnerabilities affecting different parameters (supplier_no, search, pattern, screenID, reportType) across business allocation search, audit log viewing, home page search, transaction queue viewer, and balancing reports features — all enabling database compromise. Additional issues include session fixation (CWE-384) permitting session takeover via attacker-predefined session IDs, an eval-injection weakness from unsafe inline script execution, and a reflected/stored cross-site scripting vulnerability that can execute attacker-supplied JavaScript in another user's session.
Toptech Systems notified customers directly on July 20, 2026, and all issues are resolved in release 7.8. CISA reports no known public exploitation of these vulnerabilities at this time. Vulnerabilities were reported by Sachin Shetty and Roy Duisters of Shell CyberDefence. Defenders running affected versions should prioritize patching to 7.8, restrict network exposure of these systems (they should not be internet-facing), place them behind firewalls, and use VPNs with proper hygiene for any required remote access.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,331 reports from 152 sources, 2,732 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs