CVE-2026-10763 exposes PROMOD V traffic over HTTP
The fix is simple on paper, unless a third-party Digipede dependency turns HTTPS into a scheduling problem.
TL;DR
CISA republished Hitachi Energy’s advisory for CVE-2026-10763, a CVSS 7.1 flaw in PROMOD V 1.0.10 and earlier that sends sensitive data over HTTP instead of HTTPS. Energy-sector operators should upgrade to PROMOD V 1.0.11 and enable HTTPS on Digipede servers. CISA’s notice does not say how many U.S. utilities run affected versions or when upgrades will be complete.
PROMOD V 1.0.10 and earlier have the kind of industrial-control weakness that should be boring by now: sensitive traffic moving over HTTP where HTTPS belongs. Hitachi Energy says the issue can allow interception or manipulation of data in transit, with possible credential theft, session hijacking or unauthorized access. CISA lists the vulnerability as CVE-2026-10763 with a CVSS v3.1 score of 7.1 and recommends upgrading to PROMOD V 1.0.11, then enabling HTTPS on the Digipede server.
The awkward part is the dependency. Hitachi attributes the vulnerability to a lack of HTTPS support from the third-party Digipede server, which means the remediation is not just “patch the application” in the abstract. Operators have to confirm the PROMOD V version, update the product, follow the Digipede Grid guidance in the 1.0.11 user guide or online help, and validate that control-system segmentation still holds after the change.
CISA also includes the usual ICS floor: keep control systems off the public internet, separate them from business networks, put them behind firewalls, and use updated VPNs when remote access is required. None of that replaces the actual fix. For energy operators, defense primes with energy-sector exposure, and state CISOs tracking critical infrastructure risk, Monday’s work is inventory first, upgrade second, and no assumptions that “internal” HTTP is harmless.
Published ·Deep Fathom