logo

U.S. CISA adds a new an OpenPLC ScadaBR flaw to its Known Exploited Vulnerabilities catalog

ID: b579b2a3-8b8c-5d44-b9e7-29e512a92197

STIX ID: report--b579b2a3-8b8c-5d44-b9e7-29e512a92197

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2025-12-04

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA has added two OpenPLC ScadaBR vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2021-26828 (unrestricted file upload allowing remote JSP execution, CVSS 8.7) and CVE-2021-26829 (cross-site scripting, CVSS 5.4). Federal agencies are required to remediate the issues by December 24, 2025, and organizations are advised to review the KEV catalog and patch affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.