Our takeCISA warns that Toptech RCU II+ and Multiload II+ versions before 2025-11-24 contain CVE-2026-12562, which lets attackers take full system control and reach connected networks. Patch immediately if you run these ICS devices.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:Apply the vendor patch for Toptech Systems RCU II+ and Multiload II+ released on or after 2025-11-24. If these systems are internet-exposed, isolate them immediately and review all connected network access.
What this means for you — Lean IT orgs:Update your Toptech RCU II+ or Multiload II+ units to the version released on or after 2025-11-24. If you cannot update right away, disconnect the units from the internet and limit who can reach them.
What this means for you — MSP:Check all client environments for Toptech RCU II+ and Multiload II+ deployments; patch to the 2025-11-24 release or later. Prioritize any units reachable from the internet and segment them from broader networks.
What this means for you — Researcher:CVE-2026-12562 allows full system control on unpatched Toptech RCU II+ and Multiload II+ (pre-2025-11-24). CISA ICSA-26-211-03 details the impact on connected OT networks.