<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>TopHAT (7.6.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/tophat-7.6.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 16:25:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/tophat-7.6.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in Toptech TMS7 and TopHAT</title><link>https://feed.craftedsignal.io/briefs/2026-09-toptech-vulnerabilities/</link><pubDate>Tue, 29 Sep 2026 16:25:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-toptech-vulnerabilities/</guid><description>Multiple critical vulnerabilities in Toptech TMS7 and TopHAT version 7.6.3 enable unauthenticated attackers to execute arbitrary code, manipulate databases via SQL injection, and gain unauthorized access to sensitive system files.</description><content:encoded><![CDATA[<p>Toptech Systems has disclosed multiple critical vulnerabilities affecting TMS7 and TopHAT version 7.6.3, utilized widely within the energy, chemical, and transportation sectors. These vulnerabilities range from unauthenticated file and directory access to unrestricted file uploads, SQL injection, session fixation, and cross-site scripting. The most severe flaw, CVE-2026-71379, allows unauthenticated attackers to export arbitrary database tables via crafted POST requests, while CVE-2026-70356 permits the upload and execution of arbitrary PHP files on the web server. Given the nature of these systems in industrial environments, successful exploitation could lead to full system compromise, data exfiltration, and disruption of critical infrastructure operations. Users are required to upgrade to version 7.8 or later immediately to address these flaws.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerabilities pose a severe risk to critical infrastructure sectors, including energy, chemical, and transportation systems worldwide. Successful exploitation allows for unauthenticated arbitrary code execution, database compromise via SQL injection, and access to sensitive file systems, potentially resulting in operational downtime or the exposure of sensitive industrial control data.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Toptech TMS7 and TopHAT to release 7.8 or later immediately as specified in the Toptech Systems security advisory.</li>
<li>Inspect web application logs for anomalous POST requests to file export and upload endpoints, particularly those containing suspicious file extensions or SQL syntax.</li>
<li>Enforce strict access control lists for internet-facing interfaces to limit the exposure of management consoles for TMS7 and TopHAT.</li>
<li>Monitor for unauthorized creation of new files within the web server directories, specifically looking for unexpected PHP files.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>ics</category><category>cve</category><category>web-application-vulnerability</category></item></channel></rss>