<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>OpenPDC (&lt; 2.9.482) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/openpdc--2.9.482/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 17:06:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/openpdc--2.9.482/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in Grid Protection Alliance openPDC and openHistorian</title><link>https://feed.craftedsignal.io/briefs/2026-10-grid-protection-alliance-vulns/</link><pubDate>Thu, 08 Oct 2026 17:06:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-grid-protection-alliance-vulns/</guid><description>Grid Protection Alliance openPDC and openHistorian contain multiple critical vulnerabilities, including insecure deserialization and missing authentication, allowing unauthenticated remote attackers to execute code, exfiltrate system data, or manipulate data streams.</description><content:encoded><![CDATA[<p>Grid Protection Alliance has disclosed multiple high-severity vulnerabilities affecting openPDC and openHistorian software, widely used in the energy sector for phasor data management and historian functions. The vulnerabilities include CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022, and CVE-2026-105278.</p>
<p>The most critical flaw (CVE-2026-100730) involves insecure deserialization within the service console interface, which, in deployments without Windows Authentication, allows unauthenticated network attackers to achieve remote code execution (RCE) with the privileges of the service account. Other flaws include missing authentication on data publishing interfaces (CVE-2026-105281, CVE-2026-85479), which enable unauthorized access to system topology and measurement data. These vulnerabilities pose a significant threat to industrial control environments, as they may allow attackers to gain persistent access or manipulate grid monitoring data.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation could result in full system compromise, unauthorized exfiltration of sensitive energy grid measurement data, and potential disruption to monitoring capabilities. Organizations relying on these tools for critical infrastructure visibility are at risk of unauthorized access if internet-facing or unsegmented network interfaces remain exposed. There are no fixes planned for Docker image deployments, necessitating immediate mitigation for those instances.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch affected systems by upgrading openPDC to version 2.9.482 or later and openHistorian to version 2.8.585 or later.</li>
<li>Audit network configurations to ensure internal data publisher interfaces are bound exclusively to the local loopback address. Existing installations do not automatically update this binding upon upgrade and require manual verification.</li>
<li>Discontinue the use of published Docker images for production workloads, as the vendor does not provide security patches for these containers.</li>
<li>Restrict network access to the service console interface and data publisher ports to trusted management subnets only.</li>
<li>Enable Windows Authentication for services where supported to provide an additional layer of defense against unauthenticated access.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>