Executive Summary
CVE-2026-9852 is a CSV injection flaw in Hitachi Energy MicroSCADA X SYS600 where malicious formulas planted in log messages are executed when an operator exports those logs to a spreadsheet, resulting in data exfiltration or code execution on the operator machine. Because SYS600 is the human machine interface for substation and grid automation, a compromised operator workstation sits directly adjacent to the control layer for high voltage switching and protection functions.
Technical Exposure Breakdown
The vulnerable component is the SYS600 log handling path that feeds spreadsheet export functionality. According to the grounding data, the flaw affects MicroSCADA X SYS600 versions 10.0 through 10.7. CVSS is reported at 7.8. Patch status is unknown at time of writing.
CSV injection is not a defect in the spreadsheet application. It is a trust failure at the boundary where SYS600 writes attacker-influenced text into a file that a spreadsheet program later interprets as executable content. When a log entry begins with a character such as =, +, -, or @, the spreadsheet parser treats the cell as a formula rather than a string. That formula can reference external data, build hyperlinks that leak information on click, or invoke dynamic data exchange and command execution depending on how the receiving environment is configured.
The precondition an attacker needs is the ability to write arbitrary log messages. The source identifies three realistic paths for that: SCIL scripting through normal SYS600 functionality, a separate log injection weakness, or the SYS600 broker. The critical detail for defenders is that this affects all Windows users who can run the Notify service, independent of privilege level. Low privilege access to that surface is enough to seed the payload. The formula does not run at injection time. It runs later, on the workstation of whichever engineer or operator opens the exported file, which shifts execution to a potentially higher value host and defeats the assumption that low privilege access is low risk.
OT Impact and Compliance Risk
The physical concern is not the spreadsheet. It is the operator workstation that now runs attacker controlled code inside the same trust zone as SYS600 control functions. From there an adversary can pivot toward supervisory commands, manipulate displayed values, or stage persistence on a host that engineers use to interact with protection and switching logic. A poisoned log that an incident responder exports during an investigation is a plausible and dangerous scenario, because the export often happens on the most privileged troubleshooting machine.
Under IEC 62443, this maps to failures in input validation and zone and conduit boundary trust. For NERC CIP registered entities, code execution on an interactive workstation associated with a medium or high impact BES Cyber System is a CIP-005 and CIP-007 concern, and any resulting change touches CIP-010 baseline integrity. For water and pipeline operators governed by AWIA 2018 or TSA Security Directive SD-02C, the same pattern applies wherever SYS600 sits in the control architecture: the export workflow is an unmonitored trust boundary that most asset owners have not modeled.
Compensating Controls
Do not treat this as a wait for the vendor fix problem. Active scanning to fingerprint SYS600 hosts is discouraged here, since aggressive probing of the broker or Notify service can disrupt live control processes. Prioritize passive discovery instead.
- Disable formula evaluation on any workstation that opens SYS600 log exports. Configure the spreadsheet application to treat CSV cell content as text and to block dynamic data exchange and automatic external content.
- Constrain who can write to the log path. Audit SCIL script authoring rights and restrict broker access to the minimum required set of accounts and hosts.
- Establish a virtual patch at the export boundary. Sanitize or prefix leading formula trigger characters with a single quote before any file leaves SYS600 for human review.
- Concept for network detection: alert on unexpected outbound connections from operator workstations shortly after a log export event, since exfiltration formulas and hyperlink callbacks generate traffic that a Suricata rule can flag against known HMI host baselines.
- Move log review to a hardened viewer that renders content as plain text rather than a general purpose spreadsheet.
BreachSpider Intel
BreachSpider tracks CVE-2026-9852 and related SYS600 exposure across affected version ranges so OT teams can monitor patch availability and exploitation signals without probing live control systems.