Security1 publisherNot yet confirmed elsewhere2 min readPublished
openPDC's Docker image carries all six CVEs listed in CISA advisory
CISA lists six CVEs in Grid Protection Alliance's openPDC and openHistorian, all six affecting the openPDC Docker image. Every affected range in the advisory ends below openPDC 2.9.482 and openHistorian 2.8.585, so those builds are the minimum versions energy operators should upgrade to.
The Watch · Security desk

What happened
- Native openPDC and openHistorian installs carry five of the six CVEs, and CVE-2026-105278 is listed only against the openPDC Docker image.
- When the advisory was released, CISA had received no reports of public exploitation specifically targeting these vulnerabilities.
- Shubham Raj (Cipher) of Causal Security reported the vulnerabilities to CISA.
- CISA lists energy as the affected critical infrastructure sector, with the products deployed worldwide by a vendor headquartered in the United States.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Sites running openPDC in a container have to swap in a fixed image. The sixth CVE is listed against the image itself, so a clean native install does not cover it.
- constraint One version rule cannot cover a mixed estate. openPDC and openHistorian sit on separate 2.9 and 2.8 version trains, each with its own minimum safe build.
- exposure With no exploitation reported, the instances at real risk are the ones reachable from the internet or from a business network. Those are the two placements CISA tells operators to remove.
The advisory text is not enough to rate how exploitable these flaws are. For each product, CISA's listing gives CVE identifiers and version thresholds [11]. It does not say what any of the six flaws lets an attacker do, or how severe each one is [11].
The version thresholds hold the detail operators can act on. Each product is listed against two bounds: openPDC below 2.9.477 and below 2.9.482 [1], and openHistorian below 2.8.580 and below 2.8.585 [3]. The Docker image is listed against the same two bounds as a native openPDC install [17]. On the listing as written, reaching the lower number does not take a system off it. An openPDC build at 2.9.477 or later but below 2.9.482 still falls inside the second range. So does an openHistorian build from 2.8.580 up to but not including 2.8.585 [16].
CISA's mitigations are its standard set for control systems. Keep control system devices off the internet. Put control networks behind firewalls, isolated from business networks. When remote access is required, use more secure methods such as VPNs [7]. The advisory adds that VPNs can have vulnerabilities of their own and should be kept on the current version, and that a VPN "is only as secure as the connected devices" [8]. It also tells organisations to do an impact analysis and risk assessment before deploying any of these measures [12].
On the public record, this is a single disclosure made through CISA [5], with an initial release date of 2026-10-08 [9]. If your openPDC and openHistorian servers are already isolated the way CISA describes, I'd do the upgrade in the next scheduled maintenance window [6][7]. CISA asks any organisation that sees suspected malicious activity to report it, so the agency can check it against other incidents [10].
What to watch
- Publication of per-CVE descriptions and scores, which would show whether any of the six can be reached over the network without credentials.
- A CISA revision that reports exploitation, which would turn this from scheduled patching into incident response.
- Grid Protection Alliance release notes explaining why each product has two version bounds and what CVE-2026-105278 changes in the Docker image.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives15
- Confidence70
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
openPDC versions <2.9.477 and <2.9.482 are affected by CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479 and CVE-2026-101022.
- [2]
openPDC (Docker image) versions <2.9.477 and <2.9.482 are affected by CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022 and CVE-2026-105278.
- [3]
openHistorian versions <2.8.580 and <2.8.585 are affected by CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479 and CVE-2026-101022.
- [4]
The advisory lists Energy as the critical infrastructure sector, worldwide as the deployment area, and the United States as the company headquarters location.
- [5]
Shubham Raj (Cipher) of Causal Security reported these vulnerabilities to CISA.
- [6]
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
- [7]
CISA recommends minimizing network exposure so control system devices are not accessible from the internet, locating control system networks behind firewalls and isolating them from business networks, and using more secure methods such as VPNs when remote access is required.
- [8]
CISA says VPNs may have vulnerabilities and should be updated to the most current version available, and to "recognize VPN is only as secure as the connected devices."
- [9]
The advisory's initial release date is 2026-10-08.
- [10]
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
- [11]
For each affected product, the advisory's listing gives CVE identifiers and version thresholds.
- [12]
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
- [13]
The advisory lists six distinct CVEs across openPDC, the openPDC Docker image and openHistorian, and all six apply to the Docker image.
- [14]
CVE-2026-105278 appears only in the openPDC Docker image listing; native openPDC and openHistorian each carry the other five CVEs.
- [15]
Builds at or above openPDC 2.9.482 and openHistorian 2.8.585 fall outside every affected range the advisory lists; the two products are on separate 2.9.x and 2.8.x version trains.
- [16]
An openPDC build at or above 2.9.477 but below 2.9.482, or an openHistorian build at or above 2.8.580 but below 2.8.585, still falls inside a listed affected range.
- [17]
The openPDC Docker image is listed against the same version bounds (<2.9.477, <2.9.482) as native openPDC.
Sources
1 independent publisher whose own reporting we read for this story.
- cisa.govGrid Protection Alliance openPDC and openHistorian
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- ICS and OT SecurityFollow
- Vulnerability DisclosureFollow
- Energy sector cybersecurityFollow