A tool that helps keep tabs on the US power grid just racked up five vulnerability disclosures, and one of them lets an attacker run code on the system remotely.
CISA's advisory covers openPDC and openHistorian, software from Grid Protection Alliance that collects and stores synchrophasor data, the real-time measurements utilities use to monitor grid stability. The worst bug, CVE-2026-100730, scores 9.8 out of 10: a service console deserializes client-supplied data without enough validation, and on systems that skip Windows Authentication, any network attacker can trigger it to run code with the service account's privileges. Two more bugs, CVE-2026-105281 and CVE-2026-85479, come from data-publisher interfaces that accept unauthenticated connections by default, letting an outsider read the full device topology or exchange data with the system outright. The last two, CVE-2026-104629 and CVE-2026-101022, cover hard-coded credentials and a combination of unsafe reflection and server-side request forgery.
Software like this doesn't run on home networks. It runs inside utilities, which is exactly why 'accepts connections without authentication by default' is such an unwelcome phrase. Fixes exist in openPDC 2.9.482 and openHistorian 2.8.585, but they don't apply themselves: anyone who upgraded from an older version keeps the old, open configuration unless they go back and rebind the interface manually.
The Docker images get no fix at all. Grid Protection Alliance's answer is that nobody should be running those in production anyway, a caveat that would carry more weight if the images weren't still sitting there, downloadable, unpatched.