Which Hitachi Energy Asset Suite versions are affected by CVE-2026-7395 and CVE-2026-11796?

CISA’s advisory identifies Hitachi Energy Asset Suite versions up to and including 9.9.0 as affected by CVE-2026-7395 and CVE-2026-11796.
Affected versions
The confirmed affected range is:
| Product | Affected version range | CVEs |
|---|---|---|
| Hitachi Energy Asset Suite | Up to and including 9.9.0 | CVE-2026-7395, CVE-2026-11796 |
If you operate Asset Suite 9.9.0 or an earlier listed version, the advisory’s affected-version language applies to you.
What the vulnerability is
CISA describes the issue as missing authentication for a critical function. The advisory says Hitachi Energy is aware of unauthenticated servlet access vulnerabilities affecting the listed Asset Suite versions.
The advisory also says exploitation could affect confidentiality, integrity, and availability.
What to check next
The context does not provide a full remediation procedure inside this summary. Operators should review CISA’s advisory and Hitachi Energy’s recommended immediate actions for the exact mitigation or remediation steps that apply to their environment.
Because advisories can be revised, use the current CISA page before making final operational decisions.
What immediate mitigation or remediation steps should Asset Suite operators take after the CISA advisory?

Operators using affected Hitachi Energy Asset Suite versions should review the CISA advisory and follow the recommended immediate actions for mitigation or remediation.
The practical next step
CISA’s advisory points readers to recommended immediate actions. The provided context does not list those steps in detail, so the safest grounded answer is to use CISA’s advisory as the operational source and apply the mitigation or remediation guidance it links or describes.
This matters because the advisory says exploitation could affect:
- Confidentiality
- Integrity
- Availability
Who should prioritize the review
The advisory applies to Hitachi Energy Asset Suite versions up to and including 9.9.0 for CVE-2026-7395 and CVE-2026-11796.
If your environment runs one of those versions, treat the advisory as directly relevant and check the listed actions before assuming your deployment is covered.
What not to infer
The available context does not provide patch numbers, workarounds, configuration steps, or a deadline. Those details should come from the CISA advisory and the vendor’s current instructions.
Check the live CISA advisory before acting, since ICS vulnerability guidance can be updated after release.
What changed in the October 06, 2026 CISA advisory for Hitachi Energy Asset Suite?

CISA issued an ICS advisory titled Hitachi Energy Asset Suite with a release date of October 06, 2026. The key update in the provided context is the identification of affected Asset Suite versions and related vulnerabilities.
What the advisory identified
The advisory says Hitachi Energy is aware of unauthenticated servlet access vulnerabilities affecting listed Asset Suite versions.
The affected versions are Asset Suite versions up to and including 9.9.0.
The CVEs named in the context are:
- CVE-2026-7395
- CVE-2026-11796
How CISA described the issue
CISA describes the issue as missing authentication for a critical function. The advisory says exploitation could affect confidentiality, integrity, and availability.
That means the advisory is not just a version note. It is a security notice for operators who may be running an affected Asset Suite version.
What remains to verify
The provided context does not include the full mitigation text. Anyone responsible for an Asset Suite deployment should consult the current CISA advisory for the recommended immediate actions and any later updates.
Sources / Learn more
Related reading
- Which Hitachi Energy REB500 versions are affected by CISA advisory ICSA-26-279-05?; What should energy-sector operators do if they use Hitachi Energy REB500 versions up to 8.3.3.1?; What changed in the October 06, 2026 CISA advisory for Hitachi Energy REB500?
- How can teams determine whether their SIMOVE Fleetmanager or SIPLANT version is affected by CVE-2026-67367?; What should Siemens SIMOVE Fleetmanager and SIPLANT users do after the September 22, 2026 CISA advisory?; What could the path traversal vulnerability allow an attacker to access?; Which SIMOVE Fleetmanager versions are listed as affected before the fixed releases?
- How do Siemens WTV676 and WTV776 operators check whether their Web Interface version is affected?; What should operators do if a Siemens WTV676 or WTV776 device enters protection mode and Web Access stops working?; Which Siemens WTV676 and WTV776 updates address the CISA denial of service advisory?
- Which ABB PCM600 versions are affected by the October 1, 2026 CISA advisory?; What should energy-sector operators check in ABB PCM600 after the CISA advisory?; What changes in risk does the PCM600 Scheduler Service vulnerability create for standard users?
![[Hitachi Energy Asset Suite]: Hitachi Energy Asset Suite CISA Advisory: Affected Versions and Mitigation](https://trendingissue.blog/wp-content/uploads/2026/10/pexels-24516614.jpg)