Skip to content
Security & Trust

Toptech says version 7.8 fixes ten flaws in TMS7 and TopHAT

CISA lists upload, database and login-session bugs in software tied to energy, chemical and transport sectors.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Toptech says version 7.8 fixes ten flaws in TMS7 and TopHAT

AI-generated image for WebPulse. About our images

Key finding

CVEs listed for TMS7 and TopHAT: 10 (Source: CISA advisory ICSA-26-272-02 (September 29, 2026))

Old web mistakes, new setting

Most of the ten flaws in CISA's new advisory will sound familiar to anyone who has run a public website. Upload a file and run it as code. Slip a hidden question into a search box. Reuse someone else's login session. These are ordinary web application errors.

What differs is the setting. CISA lists the affected products, Toptech TMS7 and TopHAT, under the energy, chemical and transportation systems sectors. The lesson here is that this industrial software, with its web front end, repeated the web's oldest mistakes. A web flaw does not become smaller because the application sits inside an operational environment.

10
CVEs listed for TMS7 and TopHAT
Source: CISA advisory ICSA-26-272-02 (September 29, 2026)

What CISA published

The advisory lists version 7.6.3 of both TMS7 and TopHAT as affected. It names ten CVE IDs, starting with CVE-2026-71379 and ending with CVE-2026-71189.

Toptech Systems sent a security advisory to its customers on July 20, 2026. The company says release 7.8 addresses the issues.

CISA credits Sachin Shetty and Roy Duisters, both of Shell CyberDefence, with raising the flaws with Toptech and with CISA.

CISA also says it has received no reports of public exploitation aimed at these vulnerabilities.

7.8
Release Toptech says addresses the issues
Source: CISA advisory ICSA-26-272-02 (September 29, 2026)

How the flaws work

Two flaws are notable for what they could give an attacker. The file export endpoint lets an unauthenticated attacker export arbitrary database tables with a crafted POST request (CWE-552). The advisory describes only this flaw as unauthenticated.

The file upload endpoint does not check file types on the server. An attacker can upload and run arbitrary PHP files on the web server (CWE-434). The advisory does not say whether this one needs a login.

Running an attacker's code on a server is generally treated as the gravest class of web flaw. That is a widely held view, not a finding in the advisory.

Five more flaws are time-based blind SQL injection (CWE-89). SQL is the language applications use to talk to their database. In this attack, the input carries a hidden database instruction. The attacker cannot see the answer. Instead, the database is told to pause if a guess is right, and the response time gives the result.

The advisory names five vulnerable inputs. They are supplier_no in the business allocation search, search in the audit log viewer, and pattern in the home page search. The other two are screenID in the electronic transaction queue viewer and reportType in the product summary report.

The last three flaws involve users and browsers. The application accepts session identifiers supplied by the user. It does not issue a new one after login. An attacker can set an ID in advance, wait for a victim to log in, and take over the session.

The application also uses unsafe functions that run inline scripts and evaluate strings as code (CWE-95). Finally, a cross-site scripting flaw (CWE-79) lets an attacker's JavaScript run in another user's browser, inside that user's session.

What the advisory does not say

It does not say how many customers use these products or how many have upgraded. It does not say which flaws need a login, apart from the export flaw.

It also does not explain how the five injection points relate. That is our analysis, not the advisory's. The five inputs sit in different features. That suggests input handling was not applied consistently. Testing one field would therefore not clear the others.

The dates also leave a gap. Toptech sent its customer notice on July 20. CISA published on September 29. The sources give no reason for the gap and no release date for 7.8. Nothing in them suggests that either party delayed.

So treat the customer notice as a question, not a verdict. Did it reach the person who owns the patching decision?

Questions for your team

Ask whether any TMS7 or TopHAT installation runs 7.6.3. Ask what the plan is to reach 7.8. Ask who received Toptech's July 20 notice.

Ask whether any of these systems can be reached from the internet. CISA's advice is to keep control systems off the internet. It also advises placing them behind firewalls and separating them from business networks.

Where remote access is needed, CISA points to VPNs. It warns that VPNs can have their own flaws. It adds that a VPN is only as secure as the devices connected to it.

CISA also asks organizations to run an impact analysis and risk assessment before deploying defensive measures. Suspected malicious activity should follow internal procedures and be reported to CISA.

July 20, 2026
Date Toptech sent its customer advisory
Source: CISA advisory ICSA-26-272-02 (September 29, 2026)

This industrial software speaks the web's language, and here it made the web's mistakes. Toptech says release 7.8 addresses them. The open question is whether that release has reached the people who run the systems.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.

CVEs in this analysis
CVE-2026-71379 CVE-2026-71189
Share this insight