Exploitation observed; activity peaked at 7 mentions and remains active
Immediate actions
Patch cloud jasperreports_io systems immediately
Assume compromise if assets are exposed
Recommended action window: Immediate (within 24h)
NVD description
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
Attackers exploiting CVE-2025-10492 in Hitachi Energy's Ellipse platform can achieve unauthenticated remote code execution, then escalate privileges and move laterally across enterprise networks. Runtime segmentation helps limit blast radius when critical infrastructure systems are compromised. #ZeroTrust#CriticalInfrastructure
🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/hitachi-energy-ellipse-2026-jasperreports-rce-vulnerability
Post summary
Attackers are actively exploiting CVE-2025-10492 in Hitachi Energy's Ellipse platform, enabling unauthenticated RCE, privilege escalation and lateral movement across enterprise networks, with no patch or mitigation mentioned.
⚠️ **Vulnerability Alert:** Jaspersoft Java Deserialization RCE in Hitachi Energy Ellipse (CVE-2025-10492)
🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 59.43%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** Ellipse <= 9.0.50
🫨 **Attack Vectors:**
- Remote unauthenticated Java deserialization via embedded Jaspersoft component (network-facing)
📝 **Summary:**
A Java deserialization flaw in the Jaspersoft reporting component of Hitachi Energy Ellipse allows unauthenticated remote code execution and can result in full system compromise of affected installations. This exposure threatens confidentiality, integrity, and availability of ICS/manufacturing environments where Ellipse is deployed.
📈 **Impact Scope:** Successful exploitation can yield unauthenticated remote code execution leading to full system compromise of affected Ellipse installations (<= 9.0.50). Impacts confidentiality, integrity, and availability of ICS/manufacturing environments where Ellipse is deployed globally.
🛡️ **Recommended Actions:**
- Follow CISA and vendor advisory and apply vendor patches when available
- If no patch available, isolate or remove the Jaspersoft reporting component and restrict network access to reporting interfaces
- Enforce network segmentation and firewall rules to limit exposure of Ellipse systems
- Deploy IDS/IPS and monitor for suspicious deserialization or RCE indicators; hunt logs and maintain offline backups
- Contact Hitachi Energy support for guidance and timeline for fixes
🪢 **Related Resources:**
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03
- https://www.cve.org/CVERecord?id=CVE-2025-10492
🏷 **Tags:** #Cybersecurity#HitachiEnergy#Jaspersoft
Post summary
Alert for critical CVE‑2025‑10492 involving Java deserialization RCE in Hitachi Energy Ellipse; no PoC or exploit yet, but immediate patch or containment steps are advised.
⚠️ **Vulnerability Alert:** Hitachi Energy Ellipse Jaspersoft Java Deserialization Remote Code Execution
📅 **Timeline:** Disclosure: N/A, Patch: N/A
🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 59.43%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** Ellipse <= 9.0.50
🫨 **Attack Vectors:**
- Remote code execution via unsafe Java deserialization in the Jaspersoft/JasperReports component (externally supplied serialized input)
📝 **Summary:**
An unauthenticated remote attacker can supply crafted serialized input to the Jaspersoft/JasperReports component embedded in Hitachi Energy Ellipse (CVE-2025-10492), leading to arbitrary code execution. Given Ellipse's use in critical manufacturing/ICS, exploitation can result in full system compromise, data integrity loss, and disruption of industrial processes.
📈 **Impact Scope:** Ellipse is deployed in critical manufacturing environments worldwide; successful exploitation can yield full system compromise, data integrity loss, and disruption of industrial control processes.
🛡️ **Recommended Actions:**
- Apply vendor patches when available and verify fixed versions with vendor/CISA advisories
- If patch unavailable, disable or isolate the Jaspersoft/JasperReports component and restrict access to trusted management networks
- Block reporting endpoints from Internet access and apply WAF/IDS rules to detect/block malicious serialized payloads
- Deploy or tune EDR/IDS for suspicious deserialization activity, monitor logs for anomalous report-generation requests, and ensure backups and IR plans are up to date
🪢 **Related Resources:**
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03
- https://www.cve.org/CVERecord?id=CVE-2025-10492
🏷 **Tags:** #Cybersecurity#HitachiEllipse#JaspersoftRCE
Post summary
This alert reports a critical remote code execution flaw (CVE‑2025‑10492) in Hitachi Energy Ellipse’s Jaspersoft/JasperReports component due to unsafe Java deserialization, with no PoC or in‑the‑wild exploitation reported. A patch is not yet available, but mitigation steps such as disabling the component and applying WAF/IDS rules are advised.
⚠️ **Vulnerability Alert:** Hitachi Energy Ellipse Jaspersoft Java Deserialization RCE (CVE-2025-10492)
📅 **Timeline:** Disclosure: Not Available; Patch: Not Available
🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 59.43%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** Ellipse versions <= 9.0.50
🫨 **Attack Vectors:**
- Unauthenticated network-accessible Java deserialization in Jaspersoft (JasperReports) leading to remote code execution
📝 **Summary:**
A Java deserialization vulnerability in the Jaspersoft component of Hitachi Energy Ellipse allows unauthenticated attackers to achieve remote code execution. Successful exploitation can lead to full system compromise of affected ICS/manufacturing environments, enabling data loss, disruption, and lateral movement.
📈 **Impact Scope:** Successful exploitation can produce remote code execution with potential full system compromise of affected Hitachi Energy Ellipse instances, impacting confidentiality, integrity, and availability of ICS assets and critical manufacturing systems.
🛡️ **Recommended Actions:**
- Follow the CISA advisory and vendor guidance immediately; apply vendor patches when released.
- Isolate affected Ellipse instances and restrict access to Jaspersoft/reporting endpoints.
- Implement network segmentation and firewall rules to limit exposure.
- Deploy WAF/IDS/IPS rules to detect or block Java deserialization payloads where possible.
- Disable or restrict report-generation features that accept external input until mitigations/patches are applied.
- Increase logging, monitoring, and perform threat hunting for exploitation indicators.
🪢 **Related Resources:**
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03
- https://www.cve.org/CVERecord?id=CVE-2025-10492
🏷 **Tags:** #Cybersecurity#ICS#HitachiEllipse
Post summary
The text alerts to a critical Java deserialization RCE (CVE‑2025‑10492) in Hitachi Energy Ellipse and focuses on mitigation steps and awaiting a vendor patch.
⚠️ **Vulnerability Alert:** Hitachi Energy Ellipse - Jaspersoft Java Deserialization RCE (CVE-2025-10492)
📅 **Timeline:** Disclosure: Unknown, Patch: Unknown
🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 59.43%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** Ellipse <= 9.0.50
🫨 **Attack Vectors:**
- Network: unauthenticated remote exploitation via Java deserialization
- No privileges required (PR:N)
- No user interaction required (UI:N)
📝 **Summary:**
A Java deserialization flaw in the Jaspersoft component used by Hitachi Energy Ellipse allows unauthenticated remote attackers to achieve remote code execution. Successful exploitation can result in full system compromise of Ellipse installations (<=9.0.50), affecting confidentiality, integrity, and availability in industrial/critical environments.
📈 **Impact Scope:** Remote code execution leading to full system compromise of Hitachi Energy Ellipse installations (<=9.0.50), including systems in critical manufacturing environments.
🛡️ **Recommended Actions:**
- Apply vendor-provided patches/updates immediately and follow CISA advisory guidance.
- If patches are not available: isolate affected systems, restrict network access to Ellipse/Jaspersoft services, and apply network filtering or WAF rules.
- Hunt and monitor: review logs and EDR for suspicious deserialization activity and anomalous web requests.
- Ensure recent offline backups and verify restoration procedures; contact Hitachi Energy for vendor-specific mitigation steps.
🪢 **Related Resources:**
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03
- https://www.cve.org/CVERecord?id=CVE-2025-10492
🏷 **Tags:** #Cybersecurity#HitachiEnergy#JaspersoftRCE
Post summary
A critical Java deserialization RCE vulnerability (CVE-2025-10492) in Hitachi Energy Ellipse has been disclosed, with no exploit available yet; immediate patching or mitigations are recommended.
⚠️ **Vulnerability Alert:** Jaspersoft (Jasper Report) Java Deserialization RCE in Hitachi Energy Ellipse (CVE-2025-10492)
📅 **Timeline:** Not Available
🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 59.43%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** Ellipse <= 9.0.50
🫨 **Attack Vectors:**
- Network (remote)
- Deserialization of untrusted data leading to RCE
📝 **Summary:**
A Java deserialization flaw in the Jaspersoft reporting component used by Hitachi Energy Ellipse (CVE-2025-10492) enables unauthenticated remote code execution via crafted serialized input. Exploitation runs code with the Ellipse process privileges, threatening control-system and critical-manufacturing environments.
📈 **Impact Scope:** Affects Hitachi Energy Ellipse deployments using the vulnerable Jaspersoft component for custom reports; successful exploitation yields remote code execution with the privileges of the affected process.
🛡️ **Recommended Actions:**
- Apply vendor patches when released or follow vendor mitigation guidance from the CISA advisory.
- Restrict access to reporting interfaces (network allowlisting/firewall), segment affected systems, and reduce Ellipse process privileges.
🪢 **Related Resources:**
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03
- https://www.cve.org/CVERecord?id=CVE-2025-10492
🏷 **Tags:** #Cybersecurity#HitachiEllipse#Jaspersoft
Post summary
This alert discloses CVE-2025-10492, a critical Java deserialization flaw in Jaspersoft used by Hitachi Energy Ellipse, providing technical details and patch/mitigation recommendations.
⚠️ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Energy Ellipse JasperReports RCE; Siemens SICAM 8 DoS (XML parsing/resource exhaustion); Yokogawa CENTUM VP hard-coded PROG password
📅 **Timeline:** Disclosure: 2025-09-16, Patch: 2026-03-30
🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 59.43%
🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories
📂 **Affected Versions:** Hitachi Ellipse ≤9.0.50
🔧 **Fixed Versions:** Vendor guidance via Hitachi PSIRT/CISA (no fixed version listed)
🫨 **Attack Vectors:**
- Java deserialization over network (remote code execution)
📝 **Summary:**
A deserialization flaw in the JasperReports component used by Hitachi Ellipse allows remote code execution, risking full system compromise. Exploitation could disrupt ICS operations, impact safety, and enable lateral movement.
📈 **Impact Scope:** ICS/OT systems — remote code execution, potential operational disruption and safety risks.
🛡️ **Recommended Actions:**
- Inventory Ellipse instances, isolate affected hosts, and follow Hitachi PSIRT/CISA guidance immediately
- Block/validate untrusted deserialization inputs and apply vendor/third‑party library mitigations
🆔 **CVE-2026-27663** | 📊 CVSS: 6.5 (MEDIUM 🟡) | 📈 EPSS: 4.82%
🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories
📂 **Affected Versions:** Siemens CPCI85 <26.10, RTUM85 <26.10, SICORE <26.10.0
🔧 **Fixed Versions:** Siemens update ≥26.10 (SICORE 26.10.0+)
🫨 **Attack Vectors:**
- High-volume request/resource exhaustion in remote operation mode (DoS)
📝 **Summary:**
A resource-exhaustion vulnerability in Siemens SICAM 8 can cause service degradation or reboot via high-volume requests, impacting availability of control systems. Operational disruption risk is significant for exposed or poorly segmented deployments.
📈 **Impact Scope:** ICS/OT systems — denial-of-service affecting availability and operational continuity.
🛡️ **Recommended Actions:**
- Apply Siemens security updates (≥26.10 / SICORE 26.10.0+) and isolate affected devices from untrusted networks
- Implement rate-limiting, request validation, and monitoring for anomalous traffic volumes
🆔 **CVE-2026-27664** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 15.74%
🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories
📂 **Affected Versions:** Siemens CPCI85 <26.10, RTUM85 <26.10, SICORE <26.10.0
🔧 **Fixed Versions:** Siemens update ≥26.10 (SICORE 26.10.0+)
🫨 **Attack Vectors:**
- Malformed XML over network leading to out-of-bounds write and service crash (DoS)
📝 **Summary:**
A crafted XML input can trigger an out‑of‑bounds write in SICAM 8, causing service crashes and denial-of-service. This threatens availability of monitoring/control functions and may require manual recovery.
📈 **Impact Scope:** ICS/OT systems — denial-of-service and potential operational safety impacts.
🛡️ **Recommended Actions:**
- Patch to Siemens 26.10+ (SICORE 26.10.0+) and restrict XML/protocol exposure via network controls
- Add input validation, monitoring for crashes, and automated restart/detection safeguards
🆔 **CVE-2025-7741** | 📊 CVSS: 2.1 (LOW 🟢) | 📈 EPSS: 4.39%
🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories
📂 **Affected Versions:** CENTUM VP R5.01.00–<R5.04.20, R6.01.00–<R6.12.00, R7.01.00
🔧 **Fixed Versions:** CENTUM VP R7.01.10, use Windows Authentication for R5/R6
🫨 **Attack Vectors:**
- Hard-coded PROG account password allowing authentication with HIS screen/local access
📝 **Summary:**
A hard-coded PROG password in CENTUM VP permits authentication if an attacker can access HIS screens, enabling unauthorized actions and privilege misuse. Risk increases where PROG permissions were elevated or HIS access is insufficiently restricted.
📈 **Impact Scope:** ICS/OT systems — unauthorized access, privilege misuse, and potential operational impact.
🛡️ **Recommended Actions:**
- Patch to R7.01.10 or switch affected R5/R6 branches to Windows Authentication; restrict HIS screen access
- Rotate credentials where possible, enforce least privilege, and monitor PROG account usage
🪢 **Related Resources:**
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-01
🏷 **Tags:** #Cybersecurity#ICS#OT
Post summary
The advisory announces multiple critical and medium‑severity industrial control system vulnerabilities, details their technical nature and impact, and provides patch guidance and mitigation steps.
⚠️ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Ellipse JasperReports RCE; Siemens SICAM 8 DoS/Out-of-bounds; Yokogawa CENTUM VP Hard-coded Password
📅 **Timeline:** Disclosure: unknown, Patch: unknown
🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 59.43%
🆔 **CVE-2026-27663** | 📊 CVSS: 6.5 (Medium 🟡) | 📈 EPSS: 4.82%
🆔 **CVE-2026-27664** | 📊 CVSS: 7.5 (High 🟠) | 📈 EPSS: 15.74%
🆔 **CVE-2025-7741** | 📊 CVSS: 4.0 (Low/Medium 🟢) | 📈 EPSS: 4.39%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** Hitachi Ellipse ≤9.0.50, Siemens SICAM 8 family (CPCI85/RTUM85/SICORE) <26.10, Yokogawa CENTUM VP R5.x affected (>=R5.01.00 <R5.04.20), Yokogawa CENTUM VP R6.x affected (>=R6.01.00 <R6.12.00), Yokogawa CENTUM VP vR7.01.00
🔧 **Fixed Versions:** Yokogawa: CENTUM VP R7.01.10 (patch) or switch R5/R6 to Windows Auth, Siemens: apply latest SICAM 8 security updates, Hitachi: update Jaspersoft per PSIRT
🫨 **Attack Vectors:**
- Java deserialization via Jaspersoft/JasperReports → remote code execution
- High-volume remote requests causing resource exhaustion (DoS)
- Malformed XML parsing → out-of-bounds write and service crash
- Hard-coded PROG account password usable from HIS screen access (local/admin interface)
📝 **Summary:**
Multiple high-impact ICS flaws affect Hitachi, Siemens and Yokogawa products: CVE-2025-10492 enables full RCE via a vulnerable Jaspersoft component in Hitachi Ellipse; CVE-2026-27663/27664 allow DoS and crashes in Siemens SICAM 8 components; CVE-2025-7741 is a hard-coded PROG password in Yokogawa CENTUM VP that can enable local privilege misuse. These issues threaten operational availability and can lead to full system compromise in critical manufacturing and energy environments.
📈 **Impact Scope:** Industrial control systems in critical manufacturing, energy, and related sectors; impacts include full RCE, denial-of-service/resource exhaustion and crashes, and local privilege misuse via hard-coded account.
🛡️ **Recommended Actions:**
- Apply vendor-provided updates/patches immediately and follow PSIRT advisories
- Isolate ICS/HMI networks, minimize exposure of management interfaces, and implement network-level filtering/throttling
- Hitachi: remediate/upgrade vulnerable Jaspersoft per PSIRT; Siemens: deploy latest SICAM 8 security updates; Yokogawa: apply R7.01.10 patch or switch R5/R6 to Windows Authentication Mode and review PROG permissions
- Monitor for abnormal requests, crashes, and unauthorized logins; test patches in lab before wide deployment
🪢 **Related Resources:**
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03
- https://www.cve.org/CVERecord?id=CVE-2025-10492
🏷 **Tags:** #Cybersecurity#ICS#OTsecurity (Remove commas and spaces between tags)
Post summary
The alert delivers a comprehensive disclosure of critical CSA/ICS vulnerabilities, outlines technical exploitation methods, and provides immediate patching and mitigation guidance.