Skip to content
Rota Nacional

Cyber ·

Critical flaws affect Toptech TMS7 and TopHAT 7.6.3

A CISA-attributed alert lists ten CVEs affecting TMS7 and TopHAT 7.6.3, with a CVSS score of 10. Toptech says the issues were fixed in version 7.8.

A CISA alert published on September 29, 2026, covers ten vulnerabilities in Toptech TMS7 and TopHAT, both version 7.6.3. The alert says successful exploitation could expose critical data or enable arbitrary code execution. It rates the severity CVSS 10, critical.

Risks described include unauthenticated export of database tables, dangerous file uploads, SQL injection, session fixation, eval injection, and cross-site scripting. The alert names energy, chemical, and transportation systems sectors, with deployments worldwide.

Toptech says the issues were fixed in version 7.8 and that it notified customers on July 20, 2026. Organizations using these products should identify installed versions, consult the vendor notice, and plan an update through their change processes. Do not assume an installation is protected without confirming its version and patch status.

To verify the report, consult the CISA ICS alert identified as ICSA-26-272-02 and Toptech’s notice about version 7.8; compare affected versions, CVE identifiers, and mitigation guidance. If using AI to analyze the notice or plan actions, do not submit credentials, personal data, or confidential infrastructure details: follow internal data policy and share only what is necessary.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free