CISA republished advisory ICSA-26-260-03 on September 17, 2026, disclosing five vulnerabilities in Hitachi Energy's FACTS Control Platform (FCP) — the control software behind Flexible AC Transmission Systems (FACTS) equipment that utilities use to stabilize voltage and power flow on high-voltage transmission lines. Two of the five flaws carry a CVSS score of 9.9, the highest severity CISA assigns short of a maximum 10.
What the Vulnerabilities Do
The advisory affects FCP versions 3.4.0 through 4.1.1 whenever the GWS (Gateway Web Server) component is present. CISA groups the five CVEs into a mix of query-injection, path-traversal, authentication-bypass, unauthenticated-service-exposure, and open-redirect weaknesses:
Advisory Summary — ICSA-26-260-03
- CVE-2024-4872 (CVSS 9.9) — Improper neutralization of special elements in data-query logic, allowing an authenticated attacker to inject code.
- CVE-2024-3980 (CVSS 9.9) — A second critical flaw in the same class, enabling full compromise of confidentiality, integrity, and availability.
- CVE-2024-3982 (CVSS 8.2) — Path traversal that can expose critical configuration files.
- CVE-2024-7940 (CVSS 8.3) — Authentication bypass via session hijacking.
- CVE-2024-7941 (CVSS 4.3) — Unauthenticated service exposure combined with an open-redirect flaw usable for phishing.
- Affected — FCP versions 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, and 4.1.1, only when the GWS component is installed.
Why This Matters for Grid and Utility Operators
FACTS devices — static VAR compensators, STATCOMs, and similar equipment — sit directly in the path of high-voltage transmission, correcting reactive power and damping oscillations that would otherwise destabilize the grid. The control platform for that equipment is not a back-office IT system: it is the software loop that keeps voltage within tolerance on lines carrying gigawatts of power.
An attacker chaining the query-injection flaw (CVE-2024-4872 or CVE-2024-3980) with the authentication-bypass bug (CVE-2024-7940) could potentially move from an exposed web interface to full control of the FCP without ever needing valid credentials, according to the vulnerability classes CISA lists. In a worst case, that means the ability to alter grid-stabilization setpoints — a scenario with direct physical-safety and grid-reliability consequences, not just a data breach.
The open-redirect and unauthenticated-exposure issue (CVE-2024-7941), while lower severity on its own, is the kind of flaw that is frequently used as the first step in a phishing campaign against control-room operators who trust a link that appears to originate from their own FCP interface.
Recommended Actions
- Identify every FCP deployment with the GWS component enabled — the vulnerabilities only apply when that gateway web server is present, so disabling or isolating it materially reduces exposure.
- Apply Hitachi Energy's remediation guidance in security advisory 8DBD000229, referenced directly by CISA, rather than relying on generic patching alone.
- Remove FCP/GWS interfaces from any network reachable outside the control-room LAN; CISA's general mitigation includes network isolation, firewall rules, and VPN-only access for remote management.
- Monitor for anomalous session activity given the authentication-bypass-via-session-hijacking vector — unexpected session reuse from new IP ranges is a strong compromise indicator here.
Grid-equipment vendors and integrators building custom control-plane software for FACTS, SVC, or STATCOM systems can avoid this exact failure class by parameterizing every data-query call and gating session tokens to a single source IP. YuSMP Group builds industrial control and IIoT integration software with these safeguards built in from the design stage.
Source: CISA ICS Advisory ICSA-26-260-03 (republished Sep 17, 2026).