CISA Warns of OpenPLC ScadaBR File Upload Vulnerability Exploited in Attacks
ID: 51da404d-0378-598f-ac99-6ea81dc56c9b
STIX ID: report--51da404d-0378-598f-ac99-6ea81dc56c9b
Feed Name: cybersecurityNews.com
**Executive Summary:** CISA added CVE-2021-26828 — a critical unrestricted file upload vulnerability in OpenPLC ScadaBR — to its Known Exploited Vulnerabilities catalog; authenticated attackers can upload and execute JSP files via the view_edit.shtm interface, enabling remote code execution in industrial control systems. CISA urges immediate remediation (deadline Dec 24, 2025), vendor mitigations or discontinuation where necessary, and recommends segmentation, upload restrictions, log review, and enhanced monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
