← Back to Feed
AVEVA Pipeline Integrity Monitor
CVE-2026-81821CVE-2026-81822CVE-2026-81823CVE-2026-81824
September 10, 2026 · CISA (US-CERT) · Severity: CRITICAL
AVEVA Pipeline Integrity Monitor versions up to 2025_SP1_P1 build 7.1.9580.8513 are affected by multiple vulnerabilities including use of hard-coded credentials. Successful exploitation could allow an attacker to disclose sensitive information, brute-force password hashes, or execute arbitrary code in a browser session. The vulnerabilities are tracked as CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, and CVE-2026-81824 with a CVSS v3 base score of 8.4.
Key Takeaways
- AVEVA Pipeline Integrity Monitor versions up to 2025_SP1_P1 contain hard-coded credential vulnerabilities rated CVSS 8.4 affecting pipeline monitoring infrastructure.
- Attackers exploiting these flaws could disclose sensitive pipeline information, brute-force hashes, or execute arbitrary code within user browser sessions.
- Organizations in the energy sector using AVEVA Pipeline Integrity Monitor should apply vendor updates to prevent unauthorized access to pipeline data.