🚨 #ALERT — TOPTECH TMS7 / TOPHAT: TEN FLAWS REACH CVSS 10 AND CAN EXPOSE CRITICAL DATA OR ENABLE ARBITRARY CODE EXECUTION
September 29, 2026
DISCLOSED BY:
CISA ICS
PRODUCT:
Toptech TMS7
Toptech TopHAT
CVE:
CVE-2026-63713
CVE-2026-68068
CVE-2026-68954
CVE-2026-69662
CVE-2026-70356
CVE-2026-71189
CVE-2026-71302
CVE-2026-71379
CVE-2026-72507
CVE-2026-72510
AFFECTED VERSIONS:
TMS7 7.6.3
TopHAT 7.6.3
IMPACT:
CISA states successful exploitation of the vulnerability set could expose critical data or enable arbitrary code execution. The issues span multiple weakness classes, including externally accessible files/directories and insufficient restrictions around sensitive functionality.
CVSS:
Up to 10.0 Critical
EXPLOITATION STATUS:
VULNERABILITIES CONFIRMED
NO CONFIRMED IN-THE-WILD EXPLOITATION IDENTIFIED
Operational context:
Toptech TMS7 is a terminal-automation/management platform used around fuel and liquid terminals and integrates with ERP and SCADA environments, increasing the potential operational impact of compromise.
URGENT ACTION:
Apply Toptech/CISA remediation, restrict TMS7/TopHAT management exposure, segment administrative access, and review exposed systems for unauthorized accounts, files, configuration changes, and abnormal activity.
SOURCE:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02
#CyberSecurity #ThreatIntel #Toptech #ICS #OTSecurity #CriticalInfrastructure #CodeExecution #CVE