Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-12 ยท updated: 2026-09-12 ยท tags: [incident, energy-utilities] ยท confidence: high ยท severity: critical ยท affected_sectors: [energy-utilities] ยท au_impact: true

CISA has published ICSA-26-253-01, covering four vulnerabilities in AVEVA Pipeline Integrity Monitor affecting versions up to 2025 SP1 P1 build 7.1.9580.8513, with an aggregate CVSS rating of 8.4. The flaws comprise CVE-2026-81821, use of a hard-coded cryptographic key that allows anyone with read access to PIMBoards project files to decrypt and view sensitive information; CVE-2026-81822, use of a broken or risky cryptographic algorithm; CVE-2026-81823, missing authorization; and CVE-2026-81824, a cross-site scripting flaw โ€” chained, they allow information disclosure, hash brute-forcing or arbitrary code execution in a browser session. The advisory is a republication of AVEVA security bulletin AVEVA-2026-006 and CISA reports no known public exploitation. Pipeline integrity monitoring software sits on the operational technology side of midstream and downstream oil and gas operations, where it typically shares a network segment with supervisory systems and is rarely patched on the same cadence as enterprise IT, and hard-coded cryptographic keys are the class of defect that survives procurement and commissioning because they work as designed. The advisory is a quiet one, but it is the second OT-side publication this week that lands inside critical-infrastructure control paths, alongside the Siemens S7 exploitation advisory still circulating in re-reported form.

Attribute Detail
Sector Energy & Utilities
Date 2026-09-12
Source CISA
Reliability Tier 1
CVEs CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824