Skip to content
Threat Feed
critical advisory

Critical Vulnerabilities in Toptech TMS7 and TopHAT

Multiple critical vulnerabilities in Toptech TMS7 and TopHAT version 7.6.3 enable unauthenticated attackers to execute arbitrary code, manipulate databases via SQL injection, and gain unauthorized access to sensitive system files.

Toptech Systems has disclosed multiple critical vulnerabilities affecting TMS7 and TopHAT version 7.6.3, utilized widely within the energy, chemical, and transportation sectors. These vulnerabilities range from unauthenticated file and directory access to unrestricted file uploads, SQL injection, session fixation, and cross-site scripting. The most severe flaw, CVE-2026-71379, allows unauthenticated attackers to export arbitrary database tables via crafted POST requests, while CVE-2026-70356 permits the upload and execution of arbitrary PHP files on the web server. Given the nature of these systems in industrial environments, successful exploitation could lead to full system compromise, data exfiltration, and disruption of critical infrastructure operations. Users are required to upgrade to version 7.8 or later immediately to address these flaws.

Impact

The vulnerabilities pose a severe risk to critical infrastructure sectors, including energy, chemical, and transportation systems worldwide. Successful exploitation allows for unauthenticated arbitrary code execution, database compromise via SQL injection, and access to sensitive file systems, potentially resulting in operational downtime or the exposure of sensitive industrial control data.

Recommendation

  • Upgrade Toptech TMS7 and TopHAT to release 7.8 or later immediately as specified in the Toptech Systems security advisory.
  • Inspect web application logs for anomalous POST requests to file export and upload endpoints, particularly those containing suspicious file extensions or SQL syntax.
  • Enforce strict access control lists for internet-facing interfaces to limit the exposure of management consoles for TMS7 and TopHAT.
  • Monitor for unauthorized creation of new files within the web server directories, specifically looking for unexpected PHP files.

Immediate actions

Upgrade Toptech TMS7 and TopHAT to version 7.8 or later

IT Operations 24h

Mitigations

Upgrade to version 7.8

immediate IT Operations

All CVEs listed

Detection coverage 1

Detects Potential CVE-2026-70356 Exploitation - Arbitrary PHP File Upload

critical

Detects unauthorized attempts to upload PHP files via the TMS file upload endpoint.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →