CISA has published ICSA-26-253-01, covering four vulnerabilities in AVEVA Pipeline Integrity Monitor affecting versions up to 2025 SP1 P1 build 7.1.9580.8513, with an aggregate CVSS rating of 8.4. The flaws comprise CVE-2026-81821, use of a hard-coded cryptographic key that allows anyone with read access to PIMBoards project files to decrypt and view sensitive information; CVE-2026-81822, use of a broken or risky cryptographic algorithm; CVE-2026-81823, missing authorization; and CVE-2026-81824, a cross-site scripting flaw โ chained, they allow information disclosure, hash brute-forcing or arbitrary code execution in a browser session. The advisory is a republication of AVEVA security bulletin AVEVA-2026-006 and CISA reports no known public exploitation. Pipeline integrity monitoring software sits on the operational technology side of midstream and downstream oil and gas operations, where it typically shares a network segment with supervisory systems and is rarely patched on the same cadence as enterprise IT, and hard-coded cryptographic keys are the class of defect that survives procurement and commissioning because they work as designed. The advisory is a quiet one, but it is the second OT-side publication this week that lands inside critical-infrastructure control paths, alongside the Siemens S7 exploitation advisory still circulating in re-reported form.
| Attribute | Detail |
|---|---|
| Sector | Energy & Utilities |
| Date | 2026-09-12 |
| Source | CISA |
| Reliability | Tier 1 |
| CVEs | CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824 |