TL;DR
CISA published advisory ICSA-26-272-02 on September 29, 2026, covering 10 Toptech TMS7 vulnerabilities that also affect TopHAT. The worst, CVE-2026-71379, scores CVSS 10.0 and lets an unauthenticated attacker export database tables. Toptech fixed all ten in release 7.8.
- Total: 10 CVEs
- Severity: 7 Critical · 1 High · 2 Low
- Actively exploited: None confirmed
- Highest severity: 10.0 (Critical · CVSSv3) — CVE-2026-71379
- Action: Apply the latest security updates now
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-71379 | 10 | CWE-552 | Not exploited |
| CVE-2026-70356 | 9.1 | CWE-434 | Not exploited |
| CVE-2026-72510 | 9 | CWE-89 | Not exploited |
| CVE-2026-63713 | 9 | CWE-89 | Not exploited |
| CVE-2026-68954 | 9 | CWE-89 | Not exploited |
| CVE-2026-68068 | 9 | CWE-89 | Not exploited |
| CVE-2026-72507 | 9 | CWE-89 | Not exploited |
| CVE-2026-71302 | 7.1 | CWE-384 | Not exploited |
Why These Toptech TMS7 Vulnerabilities Matter
Toptech Systems builds terminal management software used in fuel and bulk liquid terminals. CISA lists the affected sectors as energy, chemical, and transportation systems, deployed worldwide. In its summary, CISA warns that “successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code.”
How the Attacks Work
Unauthenticated Data Export (CVE-2026-71379, CVSS 10.0)
According to CISA, “the file export endpoint allows any unauthenticated attacker to export arbitrary database tables.” No login is needed, which drives the maximum score.
File Upload to Code Execution (CVE-2026-70356, CVSS 9.1)
The upload feature does not enforce file types on the server. As a result, an attacker can upload and run PHP files on the web server. This flaw requires high privileges.
Five SQL Injection Flaws (CVSS 9.0)
Five parameters across search, audit log, transaction, and report features allow time-based blind SQL injection. These issues also require high privileges.
Lower-Severity Issues
The advisory also lists a session fixation bug (CVE-2026-71302, CVSS 7.1). An attacker can plant a session ID and reuse it after the victim logs in. Two low-rated issues cover unsafe script evaluation and cross-site scripting.
Affected Versions and Exploitation Status
All ten flaws affect Toptech TMS7 and TopHAT version 7.6.3. Sachin Shetty and Roy Duisters of Shell CyberDefence reported them. CISA states that “no known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.” No public proof-of-concept has been confirmed.
Patch and Mitigation Steps
Upgrade to release 7.8. Toptech alerted its customers on July 20, 2026, before CISA published. The full list is in the CISA ICS advisory for Toptech TMS7 and TopHAT.
CISA also urges operators to “minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.” Place control networks behind firewalls and use updated VPNs for remote access. Until you patch, keep TMS7 off the internet, since the most severe of these Toptech TMS7 vulnerabilities needs no credentials.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!