[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$frjSOc5PaX0_NuE4R6dqTc7lAXDDbBx5bSgGmZLpjI0E":3},{"article":4,"iocs":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":30},"4091bc53-1118-400e-beab-9d4d9105a884","Grid Protection Alliance openPDC and openHistorian","grid-protection-alliance-openpdc-and-openhistorian-fad0f7","View CSAF Summary The following versions of Grid Protection Alliance openPDC and openHistorian are affected: openPDC \u003C2.9.477, \u003C2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022) openPDC (Docker image) \u003C2.9.477, \u003C2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022, CVE-2026-105278) openHistorian \u003C2.8.580, \u003C2.8.585 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022) CVSS Vendor Equipment v3 9.8 Grid Protection Alliance openPDC 5 Vulnerabilities Deserialization of Untrusted Data, Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), Use of Hard-coded Credentials, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') Background Critical Infrastructure Sectors: Energy Countries\u002FAreas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-100730 A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account. Read More 3 Affected Products Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance has added additional validation into serialization logic in openPDC version 2.9.482 and later and openHistorian version 2.8.585 and later. Systems using Windows Authentication are additionally protected, as they require the attacker to already be authenticated to reach this function. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix planned Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance has added additional validation into serialization logic in openPDC version 2.9.482 and later and openHistorian version 2.8.585 and later. Systems using Windows Authentication are additionally protected, as they require the attacker to already be authenticated to reach this function. Additional Metrics Relevant CWE: CWE-502 Deserialization of Untrusted Data CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H 4.0 9.3 CRITICAL CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N View CVE Details CVE-2026-105281 The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system. Read More 6 Affected Products Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix planned Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix planned Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Additional Metrics Relevant CWE: CWE-306 Missing Authentication for Critical Function CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N 4.0 8.7 HIGH CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N View CVE Details CVE-2026-85479 The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it. Read More 9 Affected Products Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix planned Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix planned Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix planned Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Additional Metrics Relevant CWE: CWE-306 Missing Authentication for Critical Function CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N 4.0 6.9 MEDIUM CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:L\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N View CVE Details CVE-2026-101022 A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on which internal hosts may be targeted. An authenticated user can attempt connections to arbitrary internal network destinations, revealing which destinations are reachable. With repeated attempts, an attacker may be able to map the internal network. Read More 12 Affected Products Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Mitigation Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations Mitigation Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Mitigation Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required. Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Mitigation Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations Mitigation Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Mitigation Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required. Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Mitigation Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations Mitigation Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Mitigation Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required. Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Mitigation Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations Mitigation Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Mitigation Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required. Additional Metrics Relevant CWE: CWE-918 Server-Side Request Forgery (SSRF) CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N 4.0 5.3 MEDIUM CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:L\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N View CVE Details CVE-2026-105278 The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administrative control of the application. Read More 13 Affected Products Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix planned Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix planned Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix planned Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix planned Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix planned Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Additional Metrics Relevant CWE: CWE-798 Use of Hard-coded Credentials CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H 4.0 9.3 CRITICAL CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N View CVE Details CVE-2026-104629 A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account. Read More 16 Affected Products Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations Grid Protection Alliance openPDC \u003C2.9.477 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance has added additional verification and integrity checks of adapters in openPDC version 2.9.477 and later and openHistorian version 2.8.580 and later. Grid Protection Alliance openPDC (Docker image) \u003C2.9.477 Product Status: known_affected Remediations No fix planned Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.580 Product Status: known_affected Remediations Vendor fix Grid Protection Alliance has added additional verification and integrity checks of adapters in openPDC version 2.9.477 and later and openHistorian version 2.8.580 and later. Additional Metrics Relevant CWE: CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H 4.0 7.7 HIGH CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:L\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N View CVE Details Acknowledgments Shubham Raj (Cipher) of Causal Security reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https:\u002F\u002Fwww.cisa.gov\u002Fnotification) and this Privacy & Use policy (https:\u002F\u002Fwww.cisa.gov\u002Fprivacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and\u002For systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov\u002Fics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov\u002Fics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-10-08 Date Revision Summary 2026-10-08 1 Initial Publication Legal Notice and Terms of Use","Multiple critical vulnerabilities have been discovered in Grid Protection Alliance's openPDC and openHistorian software, impacting versions prior to 2.9.482 for openPDC and 2.8.585 for openHistorian. These vulnerabilities, including deserialization of untrusted data, missing authentication, SSRF, and hard-coded credentials, could allow unauthenticated attackers to achieve remote code execution and gain administrative control. The vendor has released patches for some versions, but Docker images are not yet fixed.","Grid Protection Alliance openPDC and openHistorian affected by multiple critical vulnerabilities.","ICS Advisory Grid Protection Alliance openPDC and openHistorian Release DateOctober 08, 2026 Alert CodeICSA-26-281-02 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary The following versions of Grid Protection Alliance openPDC and openHistorian are affected: openPDC \u003C2.9.477, \u003C2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022) openPDC (Docker image) \u003C2.9.477, \u003C2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022, CVE-2026-105278) openHistorian \u003C2.8.580, \u003C2.8.585 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022) CVSS Vendor Equipment v3 9.8 Grid Protection Alliance openPDC 5 Vulnerabilities Deserialization of Untrusted Data, Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), Use of Hard-coded Credentials, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') Background Critical Infrastructure Sectors: Energy Countries\u002FAreas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-100730 A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account. Read More 3 Affected Products Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance has added additional validation into serialization logic in openPDC version 2.9.482 and later and openHistorian version 2.8.585 and later. Systems using Windows Authentication are additionally protected, as they require the attacker to already be authenticated to reach this function. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix plannedGrid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance has added additional validation into serialization logic in openPDC version 2.9.482 and later and openHistorian version 2.8.585 and later. Systems using Windows Authentication are additionally protected, as they require the attacker to already be authenticated to reach this function. Additional Metrics Relevant CWE: CWE-502 Deserialization of Untrusted Data CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H 4.0 9.3 CRITICAL CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N View CVE Details CVE-2026-105281 The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system. Read More 6 Affected Products Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix plannedGrid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix plannedGrid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Additional Metrics Relevant CWE: CWE-306 Missing Authentication for Critical Function CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N 4.0 8.7 HIGH CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N View CVE Details CVE-2026-85479 The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it. Read More 9 Affected Products Grid Protection Alliance openPDC \u003C2.9.482 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC (Docker image) \u003C2.9.482 Product Status: known_affected Remediations No fix plannedGrid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian \u003C2.8.585 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explici","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-281-02",null,"2026-10-08T12:00:00+00:00","2026-10-08T18:00:12.34195+00:00",9,[18,21,23],{"name":19,"type":20},"openPDC","product",{"name":22,"type":20},"openHistorian",{"name":24,"type":25},"Grid Protection Alliance","vendor","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":26,"icon":13,"name":28,"slug":29},"Vulnerabilities","vulnerabilities",[31,33,38],{"category":32},{"id":26,"icon":13,"name":28,"slug":29},{"category":34},{"id":35,"icon":13,"name":36,"slug":37},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":39},{"id":40,"icon":13,"name":41,"slug":42},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[44,48,51,54,57,60],{"type":45,"value":46,"context":47},"cve","CVE-2026-104629","Vulnerability in component loading mechanism",{"type":45,"value":49,"context":50},"CVE-2026-100730","Vulnerability in service console interface deserialization",{"type":45,"value":52,"context":53},"CVE-2026-105281","Vulnerability in internal data publisher missing authentication",{"type":45,"value":55,"context":56},"CVE-2026-85479","Vulnerability in STTP-based data publisher missing authentication",{"type":45,"value":58,"context":59},"CVE-2026-101022","Vulnerability in Modbus connection feature allowing network mapping",{"type":45,"value":61,"context":62},"CVE-2026-105278","Vulnerability in Docker image with fixed administrative credential"]