Skip to the stories
Friday, 9 October 2026
Saved

Next edition

13:50

Headlines

Threat Intelligence

CISA warns of critical flaws in openPDC and openHistorian software

The Cybersecurity and Infrastructure Security Agency reported multiple deserialization vulnerabilities in openPDC and openHistorian that could allow attackers to execute arbitrary code remotely.

FTMQ Security, written by our newsroom0 views

Share

The Cybersecurity and Infrastructure Security Agency released an alert on October 8, 2026, regarding critical security vulnerabilities in Grid Protection Alliance openPDC and openHistorian software. The affected products include versions of openPDC and openHistorian prior to version 2.9.477 and version 2.9.482, including openPDC Docker images. CISA assigned five common vulnerabilities and exposures identifiers to the issues, including CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, and CVE-2026-101022. [1]

According to CISA Alerts, a service console interface within openPDC and openHistorian deserializes a client-supplied data structure. This flaw enables an attacker to trigger the deserialization of an arbitrary object graph. Successful exploitation could allow a remote user to achieve arbitrary code execution under the privileges of the affected service account. [1]

CISA Alerts noted that access requirements depend on system configuration. On systems that use Windows Authentication, an attacker must already be authenticated to reach the vulnerable function. Conversely, on systems without Windows Authentication enabled, an unauthenticated network attacker can access the interface. [1]

Share

In short

  • Grid Protection Alliance openPDC and openHistorian versions prior to 2.9.477 and 2.9.482 contain unsafe deserialization flaws.
  • Unauthenticated network attackers can execute remote code on systems that do not use Windows Authentication.
  • CISA tracked the vulnerabilities under CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, and CVE-2026-101022.

Sources

Every paragraph above points to the numbered items it rests on. Read the originals here.

  1. [1]Grid Protection Alliance openPDC and openHistorianCISA Alerts, 13h ago (the report this story comes from)

Background

  1. [2]National Grid plc on Wikipedia

Our newsroom writes these reports with the help of software, from the 2 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.

Earlier reports of ours on the same people and subjects.

More in Threat Intelligence

Get the day in one email

Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments

Loading

Join the conversation

Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.

Already on the list? Enter the same address and we will send a sign-in link.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.