CVE-2026-8065

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-29); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-29: 1Mentions · 2026-09-30: 109-2909-30
Referenced assets2 URLs
Full discourse2 posts
  • mürrez@murrezsec

    🚨 CVE-2026-8065 PoC Released 🔴 Remote Code Execution 📌 Affected: ≤ 2026.2.14 PoC & details: https://pocbit.org/pocs/cve-2026-8065 #CVE #RCE #CyberSecurity #InfoSec #PoC #SecurityResearch

    0001064
    625 followersView on X
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen Hitachi Energy RTU500: Kritische Schwachstellen erlauben Firmware-Upload und Dateischreiben ohne Anmeldung #cve20268065 #cve20268066 #hitachienergy #rtu500 https://cybersecurity-news.de/hitachi-energy-rtu500-cve-2026-8065-cve-2026-8066

    0000028
    14 followersView on X

Explore more