
🚨 #ALERT — TOPTECH TMS7 / TOPHAT: TEN FLAWS REACH CVSS 10 AND CAN EXPOSE CRITICAL DATA OR ENABLE ARBITRARY CODE EXECUTION September 29, 2026 DISCLOSED BY: CISA ICS PRODUCT: Toptech TMS7 Toptech TopHAT CVE: CVE-2026-63713 CVE-2026-68068 CVE-2026-68954 CVE-2026-69662 CVE-2026-70356 CVE-2026-71189 CVE-2026-71302 CVE-2026-71379 CVE-2026-72507 CVE-2026-72510 AFFECTED VERSIONS: TMS7 7.6.3 TopHAT 7.6.3 IMPACT: CISA states successful exploitation of the vulnerability set could expose critical data or enable arbitrary code execution. The issues span multiple weakness classes, including externally accessible files/directories and insufficient restrictions around sensitive functionality. CVSS: Up to 10.0 Critical EXPLOITATION STATUS: VULNERABILITIES CONFIRMED NO CONFIRMED IN-THE-WILD EXPLOITATION IDENTIFIED Operational context: Toptech TMS7 is a terminal-automation/management platform used around fuel and liquid terminals and integrates with ERP and SCADA environments, increasing the potential operational impact of compromise. URGENT ACTION: Apply Toptech/CISA remediation, restrict TMS7/TopHAT management exposure, segment administrative access, and review exposed systems for unauthorized accounts, files, configuration changes, and abnormal activity. SOURCE: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02 #CyberSecurity #ThreatIntel #Toptech #ICS #OTSecurity #CriticalInfrastructure #CodeExecution #CVE
