PatchSiren cyber security CVE debrief
CVE-2026-1507 AVEVA CVE debrief
CVE-2026-1507 is a high-severity availability issue in AVEVA PI Data Archive / PI Server. According to the CISA CSAF advisory, an unauthenticated attacker can trigger an uncaught exception that may remotely crash core PI services, resulting in denial of service. For industrial and OT environments, the main concern is service disruption rather than data theft or code execution.
- Vendor
- AVEVA
- Product
- PI Data Archive PI Server
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-10
- Original CVE updated
- 2026-02-10
- Advisory published
- 2026-02-10
- Advisory updated
- 2026-02-10
Who should care
Organizations running AVEVA PI Data Archive / PI Server, especially industrial control and OT teams responsible for availability of PI services. Sites using PI Data Archive delivered by PI Server 2018 SP3 Patch 7 or earlier should treat this as urgent.
Technical summary
The advisory describes an uncaught exception in affected PI Data Archive products. Because the condition can be reached remotely without authentication, an attacker could crash core PI services and disrupt availability. The provided CVSS vector reflects network reachability, no privileges or user interaction required, and high availability impact (CVSS v3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Defensive priority
High. The issue is remotely reachable, requires no authentication, and affects service availability in OT environments where PI services may be operationally critical.
Recommended defensive actions
- Upgrade affected PI Data Archive installations to PI Server 2024 R2 or later, as recommended by AVEVA.
- If you are running PI Server 2018 SP3 Patch 7 or earlier, upgrade to PI Server 2018 SP3 Patch 8 or higher.
- Monitor the liveness of services listed in the installation's \PI\adm\pisrvstart.bat file.
- Configure PI Data Archive subsystem services to automatically restart.
- Restrict inbound access to PI Data Archive port 5450 to trusted workstations, users, and software.
- Review and follow the AVEVA security bulletin referenced in the advisory for environment-specific guidance.
Evidence notes
All core claims are taken from the CISA CSAF advisory for ICSA-26-041-03 / CVE-2026-1507. The advisory states that affected products are vulnerable to an uncaught exception that could allow an unauthenticated attacker to remotely crash core PI services, causing denial of service. Remediation guidance in the same advisory includes upgrading to PI Server 2024 R2 or later, or to PI Server 2018 SP3 Patch 8 or higher for older deployments, plus defensive measures such as service monitoring, automatic restarts, and limiting inbound access to port 5450. Timing context uses the CVE published/modified date of 2026-02-10.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-1507 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-1507
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-1507 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-1507
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-041-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-041-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.