VulnSea

Hitachi Energy has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 8.5 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-306 (3). Most affected products: RTU500 series CMU firmware (3), Asset Suite (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.5
Publish → KEV
—
Last 90 days
5 prev 0

Products

  • RTU500 series CMU firmware 3
  • Asset Suite 2
5
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

Hitachi Energy vulnerabilities

CVEs affecting Hitachi Energy, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-8067Medium· 6.5
today

An improper authorization vulnerability in the RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint

An improper authorization vulnerability in the RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disr…

▾ SunlitHitachi Energy · RTU500 series CMU firmwarevia NVD
CVE-2026-7395High· 8.5
today

Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise

Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specificall…

▾ TwilightHitachi Energy · Asset Suitevia NVD
CVE-2026-11796Medium· 5.1
today

Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availabili…

Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availabili…

▾ SunlitHitachi Energy · Asset Suitevia NVD
CVE-2026-8065Critical· 9.1
today

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attac…

▾ MidnightHitachi Energy · RTU500 series CMU firmwarevia NVD
CVE-2026-8066Critical· 9.1
today

A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system

A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful…

▾ MidnightHitachi Energy · RTU500 series CMU firmwarevia NVD
Hitachi Energy vulnerabilities (CVEs) · VulnSea