Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

openPDC's Docker image carries all six CVEs listed in CISA advisory

CISA lists six CVEs in Grid Protection Alliance's openPDC and openHistorian, all six affecting the openPDC Docker image. Every affected range in the advisory ends below openPDC 2.9.482 and openHistorian 2.8.585, so those builds are the minimum versions energy operators should upgrade to.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying openPDC's Docker image carries all six CVEs listed in CISA advisory
Generated illustration

What happened

  • Native openPDC and openHistorian installs carry five of the six CVEs, and CVE-2026-105278 is listed only against the openPDC Docker image.
  • When the advisory was released, CISA had received no reports of public exploitation specifically targeting these vulnerabilities.
  • Shubham Raj (Cipher) of Causal Security reported the vulnerabilities to CISA.
  • CISA lists energy as the affected critical infrastructure sector, with the products deployed worldwide by a vendor headquartered in the United States.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Sites running openPDC in a container have to swap in a fixed image. The sixth CVE is listed against the image itself, so a clean native install does not cover it.
  • constraint One version rule cannot cover a mixed estate. openPDC and openHistorian sit on separate 2.9 and 2.8 version trains, each with its own minimum safe build.
  • exposure With no exploitation reported, the instances at real risk are the ones reachable from the internet or from a business network. Those are the two placements CISA tells operators to remove.

The advisory text is not enough to rate how exploitable these flaws are. For each product, CISA's listing gives CVE identifiers and version thresholds [11]. It does not say what any of the six flaws lets an attacker do, or how severe each one is [11].

The version thresholds hold the detail operators can act on. Each product is listed against two bounds: openPDC below 2.9.477 and below 2.9.482 [1], and openHistorian below 2.8.580 and below 2.8.585 [3]. The Docker image is listed against the same two bounds as a native openPDC install [17]. On the listing as written, reaching the lower number does not take a system off it. An openPDC build at 2.9.477 or later but below 2.9.482 still falls inside the second range. So does an openHistorian build from 2.8.580 up to but not including 2.8.585 [16].

CISA's mitigations are its standard set for control systems. Keep control system devices off the internet. Put control networks behind firewalls, isolated from business networks. When remote access is required, use more secure methods such as VPNs [7]. The advisory adds that VPNs can have vulnerabilities of their own and should be kept on the current version, and that a VPN "is only as secure as the connected devices" [8]. It also tells organisations to do an impact analysis and risk assessment before deploying any of these measures [12].

On the public record, this is a single disclosure made through CISA [5], with an initial release date of 2026-10-08 [9]. If your openPDC and openHistorian servers are already isolated the way CISA describes, I'd do the upgrade in the next scheduled maintenance window [6][7]. CISA asks any organisation that sees suspected malicious activity to report it, so the agency can check it against other incidents [10].

What to watch

  • Publication of per-CVE descriptions and scores, which would show whether any of the six can be reached over the network without credentials.
  • A CISA revision that reports exploitation, which would turn this from scheduled patching into incident response.
  • Grid Protection Alliance release notes explaining why each product has two version bounds and what CVE-2026-105278 changes in the Docker image.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence72
Adoption
Insufficient
Hype gap0
Incentives15
Confidence70
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    openPDC versions <2.9.477 and <2.9.482 are affected by CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479 and CVE-2026-101022.

    ReportedSupportedSource: CISA advisory ICSA-26-281-02View cited source
  2. [2]

    openPDC (Docker image) versions <2.9.477 and <2.9.482 are affected by CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022 and CVE-2026-105278.

    ReportedSupportedSource: CISA advisory ICSA-26-281-02View cited source
  3. [3]

    openHistorian versions <2.8.580 and <2.8.585 are affected by CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479 and CVE-2026-101022.

    ReportedSupportedSource: CISA advisory ICSA-26-281-02View cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. cisa.gov

    1 article · October 8, 2026

    Grid Protection Alliance openPDC and openHistorian

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories