Historical intelligence backfill. This assessment covers reporting originally published on 2026-06-09 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

Vertiv UPS cards had 9.8s that translate to "output OFF" for a data hall

CVE-2025-46412 (auth bypass) plus CVE-2025-41426 (stack overflow RCE) on Liebert IS-UNITY-DP network cards — Claroty showed the UPS language for shutting down powered loads.

RWP Ventures · 2026-09-07 · event 2026-06-09 · 1 min read · priority 8.6

Bottom line up front

CONFIRMED On 9 June 2026 Team82 published two CVSS 9.8 issues on Vertiv Liebert IS-UNITY-DP cards that give UPS devices a web NIC: CVE-2025-46412 authentication bypass on the web UI, CVE-2025-41426 stack-based buffer overflow for RCE. Chained, unauthenticated remote control of the UPS. Claroty's operational punchline is the "output OFF" command — in UPS language, drop the load. Presented at SANS ICS Summit 2026 with the Trane HVAC chain (separate post). Vendors patched before publication. SecurityWeek and Cyber Risk Leaders corroborate. No named victim outage. Process/facility impact: ASSESSED if a reachable card is unpatched, not CONFIRMED in production.

Historical backfill of 9 June 2026 reporting; added 7 September 2026.

What happened

Researchers hot-wired the card without buying a room-sized UPS. The interesting bit is not the overflow — it is that the management plane can command power state.

Why it mattered

AI halls already treat cooling and power as the scarce resource. A NIC on the UPS is in the blast radius of "critical infrastructure" whether the CISO's asset list says so.

Who / what was affected

Liebert IS-UNITY-DP deployments, especially data-center UPS fleets. Internet-exposed cards are the realistic condition.

Technical context

Patch the card firmware; take the web UI off the internet; out-of-band management only; alert on unexpected UPS output-off.

Exploitation / threat status at the time

CONFIRMED vulns, scores, vendor remediation.

UNKNOWN exploitation.

What defenders should have done

  1. Inventory UNITY-DP.
  2. Management VRF, not tenant LAN.
  3. Tabletop: simultaneous HVAC + UPS (the paired talk).

RWP assessment

Confidence: High on the technical claims. Do not wait for a public ransomware note that mentions Vertiv.

Defensive actions

  1. Firmware now.
  2. No default web on WAN.
  3. Correlate UPS SNMP traps with SOC, not just facilities.

Sources

  1. Claroty Team82 — Attacking UPS network cards to take down data centers
  2. SecurityWeek — Critical HVAC and UPS vulnerabilities could let hackers disrupt data centers
  3. Cyber Risk Leaders — Claroty flags Vertiv UPS cards and Trane HVAC