ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds new OpenPLC ScadaBR flaw to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2021-26828CVE-2021-26829

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-26828
+1 in the same advisory: …26829
Authenticated JSP File Upload RCE in OpenPLC ScadaBR (view_edit.shtm)

OpenPLC ScadaBR contains an unrestricted file upload flaw (CWE-434) in its web interface that lets a remote, authenticated user upload arbitrary JSP files through view_edit.shtm. Once uploaded, the malicious JSP is executed by the application server, giving the attacker remote code execution on the host running ScadaBR. Because exploitation requires valid credentials, risk is highest in deployments where default, shared, or weak passwords are used, which is common in OT/SCADA environments. The flaw affects OpenPLC's ScadaBR SCADA/HMI software. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-03, confirming active exploitation in the wild, and EPSS puts its 30-day exploitation probability at 39.4% (99th percentile); no public PoC is known.

Do: Update ScadaBR/OpenPLC to the latest vendor release per vendor guidance, as required by CISA's KEV listing and BOD 22-01 for federal agencies. Until patched, restrict access to the ScadaBR web interface (including view_edit.shtm) to trusted users and networks, enforce strong unique credentials since exploitation requires authentication, and check the ScadaBR webapps/upload directories and access logs for unexpected .jsp files or recent uploads.

8.8
group max
39% KEV PoC ×3
  • OpenPLC ScadaBR
moderate~1,000-3,000 internet-exposed ScadaBR instances (rough order-of-magnitude estimate)
Full article240 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 04, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a new OpenPLC ScadaBR flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an OpenPLC ScadaBR flaw, tracked as CVE-2021-26828 (CVSS Score of 8.7), to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability is an unrestricted upload of file with dangerous type vulnerability. 

“OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.” reads the advisory.

Early this week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added another OpenPLC ScadaBR flaw, tracked as CVE-2021-26829  (CVSS score of 5.4), to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability is a cross-site scripting (XSS) flaw that impacts Windows and Linux versions via system_settings.shtm. The vulnerability impacts OpenPLC ScadaBR through 1.12.4 on Windows and OpenPLC ScadaBR through 0.9.1 on Linux.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by December 24, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185327/hacking/u-s-cisa-adds-new-openplc-scadabr-flaw-to-its-known-exploited-vulnerabilities-catalog.html