OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-8066

CRITICAL · CVSS 9.1 EPSS 0.74% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A critical directory traversal vulnerability in the file upload feature of Hitachi Energy RTU500 devices allows unauthenticated attackers to write or overwrite arbitrary files on the device's file system. Exploitation could lead to unauthorized modifications of device data or disrupt normal operations, posing significant risks to system integrity and availability. Organizations using RTU500 devices should prioritize immediate remediation to mitigate potential impacts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-8066
Severity
CRITICAL
CVSS
9.1
EPSS
0.74%

Original NVD Description

A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.