CVE-2026-9853: Hitachienergy Microscada X SYS600
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SYS600 system users should be permitted to view and modify application objects.
Affected products
- Hitachienergy Microscada X SYS600: from 10.0, up to and including 10.8
Published 2026-09-03. Last modified 2026-09-09.