{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/toptech-systems/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TMS7 (7.6.3)","TopHAT (7.6.3)"],"_cs_severities":["critical"],"_cs_tags":["ics","cve","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Toptech Systems"],"content_html":"\u003cp\u003eToptech Systems has disclosed multiple critical vulnerabilities affecting TMS7 and TopHAT version 7.6.3, utilized widely within the energy, chemical, and transportation sectors. These vulnerabilities range from unauthenticated file and directory access to unrestricted file uploads, SQL injection, session fixation, and cross-site scripting. The most severe flaw, CVE-2026-71379, allows unauthenticated attackers to export arbitrary database tables via crafted POST requests, while CVE-2026-70356 permits the upload and execution of arbitrary PHP files on the web server. Given the nature of these systems in industrial environments, successful exploitation could lead to full system compromise, data exfiltration, and disruption of critical infrastructure operations. Users are required to upgrade to version 7.8 or later immediately to address these flaws.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerabilities pose a severe risk to critical infrastructure sectors, including energy, chemical, and transportation systems worldwide. Successful exploitation allows for unauthenticated arbitrary code execution, database compromise via SQL injection, and access to sensitive file systems, potentially resulting in operational downtime or the exposure of sensitive industrial control data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Toptech TMS7 and TopHAT to release 7.8 or later immediately as specified in the Toptech Systems security advisory.\u003c/li\u003e\n\u003cli\u003eInspect web application logs for anomalous POST requests to file export and upload endpoints, particularly those containing suspicious file extensions or SQL syntax.\u003c/li\u003e\n\u003cli\u003eEnforce strict access control lists for internet-facing interfaces to limit the exposure of management consoles for TMS7 and TopHAT.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized creation of new files within the web server directories, specifically looking for unexpected PHP files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T16:25:29Z","date_published":"2026-09-29T16:25:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-toptech-vulnerabilities/","summary":"Multiple critical vulnerabilities in Toptech TMS7 and TopHAT version 7.6.3 enable unauthenticated attackers to execute arbitrary code, manipulate databases via SQL injection, and gain unauthorized access to sensitive system files.","title":"Critical Vulnerabilities in Toptech TMS7 and TopHAT","url":"https://feed.craftedsignal.io/briefs/2026-09-toptech-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Toptech Systems","version":"https://jsonfeed.org/version/1.1"}