The Power Grid Runs on Borrowed Code — and Some of It Can Never Be Patched
The software that helps run electrical substations and grid operations just got hit with four security advisories in a single batch — including a remote code execution flaw rated 8.8 out of 10 in severity. That's the kind of vulnerability that lets an attacker run their own commands on grid-management systems. The deeper problem isn't any single bug; it's what this cluster of advisories reveals about how the grid's software actually gets built and maintained.
Bottom Line
THE BOTTOM LINE: Four simultaneous advisories for one major grid-equipment vendor isn't a crisis — it's a diagnosis. The electrical grid increasingly runs on the same open-source building blocks as the rest of the internet, inheriting their flaws, while some of its hardware is too old to ever be fixed. No exploitation has been reported, and disclosure-plus-mitigation is the system working as designed. But the gap between disclosure and deployed fixes in operational technology is measured in months or years, not days — and that gap is the real vulnerability.