# Toptech TMS7/TopHAT fuel systems get 10 CVEs patched

Published: 2026-09-29 · Severity: routine · Sectors: energy, transportation, manufacturing
Canonical: https://vorant.io/reports/f1e4f959-538d-5a67-80dd-7fa97ce5ffba/toptech-tms7-tophat-fuel-systems-get-10-cves-patched

> CISA discloses 10 vulnerabilities in Toptech TMS7 and TopHAT fuel management systems, including unauthenticated data export, RCE via file upload, and multiple SQL injections; fixed in v7.8.

CISA published an ICS advisory covering ten vulnerabilities in Toptech Systems' TMS7 and TopHAT fuel/tank management software (version 7.6.3), used across energy, chemical, and transportation sector organizations worldwide. The most severe issue (CVE-2026-71379) allows any unauthenticated attacker to export arbitrary database tables via a crafted POST request to the file export endpoint. A second critical flaw (CVE-2026-70356) lets an attacker bypass server-side file type restrictions on the TMS file upload endpoint to upload and execute arbitrary PHP files, achieving remote code execution on the web server.

The advisory also lists five separate time-based blind SQL injection vulnerabilities affecting different parameters (supplier_no, search, pattern, screenID, reportType) across business allocation search, audit log viewing, home page search, transaction queue viewer, and balancing reports features — all enabling database compromise. Additional issues include session fixation (CWE-384) permitting session takeover via attacker-predefined session IDs, an eval-injection weakness from unsafe inline script execution, and a reflected/stored cross-site scripting vulnerability that can execute attacker-supplied JavaScript in another user's session.

Toptech Systems notified customers directly on July 20, 2026, and all issues are resolved in release 7.8. CISA reports no known public exploitation of these vulnerabilities at this time. Vulnerabilities were reported by Sachin Shetty and Roy Duisters of Shell CyberDefence. Defenders running affected versions should prioritize patching to 7.8, restrict network exposure of these systems (they should not be internet-facing), place them behind firewalls, and use VPNs with proper hygiene for any required remote access.

## Mentioned in this report

- Vulnerabilities: CVE-2026-63713, CVE-2026-68068, CVE-2026-68954, CVE-2026-69662, CVE-2026-70356, CVE-2026-71189, CVE-2026-71302, CVE-2026-71379, CVE-2026-72507, CVE-2026-72510

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f1e4f959-538d-5a67-80dd-7fa97ce5ffba/toptech-tms7-tophat-fuel-systems-get-10-cves-patched.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
