CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV
A security vulnerability affecting OpenPLC ScadaBR has been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) list, citing evidence of active exploitation.
The vulnerability in question is CVE-2021-26829 (CVSS score: 5.4), a cross-site scripting (XSS) bug that affects Windows and Linux versions of the software via system_settings.shtm. It affects the versions listed below:
OpenPLC ScadaBR through 1.12.4 on Windows
OpenPLC ScadaBR through 0.9.1 on Linux
The security flaw was added to the KEV catalog just over a month after Forescout claimed to have discovered TwoNet, a pro-Russian hacktivist group, attacking its honeypot in September 2025 after mistaking it for a water treatment plant.
The threat actor in the ...

