CISA published an ICS advisory for Yokogawa FAST/TOOLS (affected versions R9.01 through R10.04) warning that successful exploitation of multiple web-facing weaknesses could enable man-in-the-middle (MITM) interception, redirection to malicious sites, malicious script execution, and file theft/disclosure, among other impacts. The advisory enumerates a broad set of issues spanning information exposure, CSRF, cleartext transmission, weak/broken cryptography, improper security checks, reliance on IP address for authentication, insufficient input validation, and path traversal, with deployment noted as worldwide across critical infrastructure environments.
Yokogawa’s associated vulnerability disclosures (as reflected in CVE records) include CVE-2025-66600 (missing/insufficient HSTS enabling MITM sniffing of web communications), CVE-2025-66597 (support for weak cryptographic algorithms that may allow decryption of web-server communications), and CVE-2025-66608 (improper URL validation that could allow an attacker to send crafted requests to steal files from the web server). These CVEs align with the CISA advisory’s broader risk statement that exploitation could compromise confidentiality and integrity of FAST/TOOLS web interactions and exposed server-side resources in operational environments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-10, CISA published Revision 1 of advisory ICSA-26-041-01 covering multiple web-related vulnerabilities in Yokogawa FAST/TOOLS versions R9.01 through R10.04. CISA described impacts including malicious redirection, decryption of communications, man-in-the-middle attacks, script execution, unauthorized file access, and path traversal, and said it had no reports of known public exploitation at publication time.
On 2026-02-09, CVE records for multiple Yokogawa FAST/TOOLS vulnerabilities, including CVE-2025-66600, CVE-2025-66608, and CVE-2025-66597, were updated with descriptions, affected versions, CVSS v4.0 vectors, CWE classifications, and vendor advisory references. The issues included missing HSTS, improper URL validation enabling file disclosure, and weak cryptography across FAST/TOOLS versions R9.01 through R10.04.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.