CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

A security vulnerability affecting OpenPLC ScadaBR has been added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) list, citing evidence of active exploitation.

The vulnerability in question is CVE-2021-26829 (CVSS score: 5.4), a cross-site scripting (XSS) bug that affects Windows and Linux versions of the software via system_settings.shtm. It affects the versions listed below:

  • OpenPLC ScadaBR through 1.12.4 on Windows
  • OpenPLC ScadaBR through 0.9.1 on Linux

The security flaw was added to the KEV catalog just over a month after Forescout claimed to have discovered TwoNet, a pro-Russian hacktivist group, attacking its honeypot in September 2025 after mistaking it for a water treatment plant.

The threat actor in the decoy plant compromise is reported to have transitioned from first access to disruptive action in roughly 26 hours read more about CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *