The CISA advisory on Fuji Electric Tellus is another reminder that industrial software security must be treated beyond the application layer. A kernel driver granting broad read/write permissions to all users can create serious privilege and system integrity risks, especially in OT environments where availability and safety are critical.

Organizations using such systems should immediately review exposure, validate installed versions, apply vendor guidance, and ensure OT assets are isolated behind proper network security controls. In industrial environments, even a “local” weakness can become a major operational risk once an attacker gets an initial foothold. Because apparently giving everyone read/write access at kernel level is still a thing we have to warn people about in 2026.


View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to elevate privileges from user to system, which may then enable the attacker to cause a temporary denial of service, open files, or delete files. The following versions of Fuji Electric Tellus are affected: Tellus 5.0.2 CVSS Vendor Equipment Vulnerabilities v3 7.8 Fuji Electric Fuji Electric Tellus Exposed Dangerous Method or Function Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Japan Vulnerabilities Expand All + CVE-2026-8108 The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions. View CVE Details Affected Products Fuji Electric Tellus Vendor: Fuji Electric Product Version: Fuji Electric Tellus: 5.0.2 Product Status: known_affected Remediations Vendor fix Fuji Electric recommends that Tellus be installed only with administrator privileges. Relevant CWE: CWE-749 Exposed Dangerous Method or Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Acknowledgments Kim Myung-gyu of Trend Micro Zero Day Initiative reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take

Source: Fuji Electric Tellus via CISA Advisories — published 12 May 2026.