CVE-2026-8065: Hitachi Energy RTU500 Series Cmu Firmware

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.

Affected products

  • Hitachi Energy RTU500 Series Cmu Firmware: from 9.0, before 12.0 (fixed in 12.0)

Published 2026-09-29. Last modified 2026-09-29.