logo

CISA Warns of OpenPLC ScadaBR cross-site scripting vulnerability Exploited in Attacks

ID: e843e726-68b8-5b42-8172-b6596e3b4cb3

STIX ID: report--e843e726-68b8-5b42-8172-b6596e3b4cb3

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-11-29

Date Updated: 2026-04-21

Author: Guru Baran

...
...

CISA added CVE-2021-26829—an XSS vulnerability in OpenPLC ScadaBR's system_settings.shtm—to its Known Exploited Vulnerabilities catalog after observing active exploitation; the flaw can execute arbitrary script in administrator/authenticated user browsers, risking session hijack, credential theft, and configuration tampering in SCADA/OT environments, and federal agencies must remediate by December 19, 2025 under BOD 22-01.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.