CISA Flags Critical Vulnerabilities in Toptech TMS7 and TopHAT Industrial Software
CISA has issued an advisory detailing multiple critical vulnerabilities in Toptech TMS7 and TopHAT software, versions 7.6.3, which could allow attackers to access sensitive data or execute arbitrary code.

CISA has issued a critical advisory concerning multiple severe vulnerabilities affecting Toptech TMS7 and TopHAT software, specifically version 7.6.3. These vulnerabilities, if successfully exploited, could grant attackers the ability to access critical data or execute arbitrary code on affected systems, posing a significant risk to industrial control environments.
The advisory lists ten distinct CVEs affecting both TMS7 and TopHAT versions 7.6.3. The vulnerabilities span a range of common web application weaknesses, including SQL injection, unrestricted file upload, session fixation, and cross-site scripting (XSS). The severity of these issues is underscored by their CVSS v3.1 base scores, with several rated as CRITICAL, including a perfect 10.0 for CVE-2026-71379, which allows unauthenticated attackers to export arbitrary database tables.
One particularly concerning vulnerability, CVE-2026-70356, involves an unrestricted file upload flaw. This allows an attacker to upload and execute arbitrary PHP files on the web server by bypassing server-side restrictions. This could lead to full system compromise. Other SQL injection vulnerabilities, such as CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, and CVE-2026-68068, are present in various features like business allocation search and log auditing, enabling attackers to manipulate or exfiltrate sensitive database information.
The affected products, Toptech TMS7 and TopHAT, are utilized in critical infrastructure sectors including Energy, Chemical, and Transportation Systems, and are deployed worldwide. The potential for attackers to gain unauthorized access or execute code on these systems presents a substantial threat to the operational integrity and security of these vital industries.
Toptech Systems has acknowledged these vulnerabilities and has released version 7.8 of both TMS7 and TopHAT to address the security flaws. The company issued a security advisory to its customers on July 20, 2026, detailing the issues and the available patches. Users are strongly encouraged to update to the latest version to mitigate these risks.
While the vulnerabilities have been patched, the advisory serves as a stark reminder of the ongoing security challenges within the Industrial Internet of Things (IIoT) and operational technology (OT) sectors. The widespread deployment of these systems, often with long lifecycles, makes timely patching and robust security practices paramount.
Organizations using Toptech TMS7 or TopHAT are urged to review the CISA advisory and Toptech Systems' security blog for detailed information on the vulnerabilities and the remediation steps. Applying the updates promptly is crucial to prevent potential exploitation and safeguard critical infrastructure.