CVE-2026-1507: Aveva Pi Data Archive Pi Server

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The affected products are vulnerable to an uncaught exception that could allow an unauthenticated attacker to remotely crash core PI services resulting in a denial-of-service.

Affected products

  • Aveva Pi Data Archive Pi Server: up to and including 2018_SP3_Patch_7

Published 2026-02-10. Last modified 2026-06-17.