Toptech TMS7 hit by 10 CVEs, one a CVSS 10 unauthenticated database dump
The file-export flaw needs no credentials, no session, and no foothold, any attacker who can reach the server walks away with the database.
TL;DR
CISA issued an advisory covering 10 vulnerabilities in Toptech TMS7 and TopHAT 7.6.3, terminal-management software deployed across energy, chemical, and transportation infrastructure worldwide. CVE-2026-71379 scores 10.0: an unauthenticated attacker sends a crafted POST request and exports arbitrary database tables. Five additional flaws are SQL injection; another allows arbitrary PHP file upload. Toptech alerted customers on July 20, 2026 and says release 7.8 addresses all ten.
CVE-2026-71379 is the one that should make operations teams move fastest. The file-export endpoint in TMS7 and TopHAT 7.6.3 accepts a crafted POST request from anyone (no authentication, no session token) and returns the contents of whatever database table the attacker asks for. CVSS 3.1 and 4.0 both land at 10.0. That's the first maximum-severity score in a Toptech advisory, and it changes the risk calculus for every organization running these products on a reachable network segment.
The rest of the ten-CVE batch fills in the picture: CVE-2026-70356 lets an authenticated attacker upload and execute arbitrary PHP on the web server (CVSS 9.1), and five distinct SQL injection flaws sit in parameters across the application (supplier_no, search, pattern, screenID, and reportType) all time-based blind injection, all scored 9.0 under CVSS 3.1.
Toptech notified customers on July 20, 2026. The public advisory from CISA followed roughly two months later. Release 7.8 is the fix; the vendor's security blog has download details. There's no indication of a CISA binding operational directive tied to this advisory.
The concentration matters. Ten CVEs in a single product release, spanning unauthenticated data access, remote code execution, and SQL injection, is unusual for an ICS/OT vendor. It also comes on the heels of ICSA-26-211-03 from late July, which covered a missing-authentication flaw in Toptech's RCU II+ and Multiload II+ products, same vendor, same pattern of network-accessible services lacking authentication controls.
In terminal environments where TMS7 sits on a flat OT network, the unauthenticated export flaw turns one compromised host or one misconfigured firewall rule into full database exfiltration. The SQL injection flaws require authentication, which limits the blast radius but does little for organizations where shared credentials are the norm. Patch priority should route CVE-2026-71379 first, then the file-upload vector, then the injection points, but the only complete remediation is 7.8 across the board.
Published ·Deep Fathom