CVE-2026-8065 is an authentication-bypass vulnerability affecting the firmware-update endpoint in end-of-life Hitachi Energy RTU500 versions. An unauthenticated attacker can submit a crafted POST request to upload arbitrary firmware, bypassing authentication for a security-critical update function. Exploitation can alter device functionality and threaten device integrity or availability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This seven-file Python repository is a standalone alleged CVE-2026-8065 PoC, not a Metasploit/Nuclei module. poc.py is the primary entry point: it performs concurrent single-target or list-based HTTP(S) fingerprinting for RTU500/CMU markers, probes login and candidate firmware paths, and can submit an unauthenticated multipart fake-firmware upload. It supports dry-run, forced exploitation without a fingerprint, custom firmware paths, JSONL output, proxy/timeout controls, and a local lab mode. _format_fofa.py converts FOFA CSV exports into deduplicated URL lists and prioritizes likely RTU500 targets using host/title regexes. README.md documents the claimed CWE-306 issue, candidate paths, FOFA discovery queries, and safety guidance; targets.example.txt contains private/example target URLs. The code uses requests and urllib3. A key limitation is that the repository itself describes the update URIs as a curated list of likely paths and uses only a marker blob, so acceptance findings are heuristic and do not independently establish that a target has a confirmed firmware-update authentication bypass.
This six-file Python repository implements a standalone PoC for the claimed CVE-2026-8065 authentication bypass in Hitachi Energy RTU500 Series CMU firmware-update functionality. `poc.py` is the main executable: it fingerprints target web interfaces using RTU500/CMU markers, probes login and firmware-related paths over common HTTP(S) ports, and in exploit mode sends multipart POST uploads without a session cookie. Acceptance is inferred from 2xx responses and success-text heuristics; the default uploaded content is the `POCBIT-8065-FW-PROBE` marker, not a valid flash image. It supports individual targets, concurrent list-based scanning, dry-run GET-only probing, path overrides, proxying, JSON/JSONL-style results, and a local mock-lab validation mode. The exact vulnerable URI is not established by the included code: it cycles through a curated set of candidate paths, so positive results require validation and can be false positives. `_format_fofa.py` normalizes FOFA CSV exports into deduplicated HTTP(S) target lists and ranks probable RTU500 assets based on host/title keywords. The remaining files provide dependency declarations, target examples, license, and documentation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication-bypass flaw in the Hitachi Energy RTU500 firmware-update endpoint that permits unauthenticated arbitrary firmware uploads via a crafted POST request, potentially enabling modification of device functionality and compromise of device integrity or availability.
A critical, remotely exploitable authentication-bypass vulnerability in the Hitachi Energy RTU500 firmware-update endpoint. An unauthenticated attacker can submit a crafted POST request to upload arbitrary firmware, potentially modifying device functionality and compromising device integrity or availability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.