← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 22, 2026 · 12:00via CISA Alerts

OpenPLC Runtime v3

Brief

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives.

The following versions of OpenPLC Runtime v3 are affected:

  • OpenPLC 3 (CVE-2026-88020)

CVSS

Vendor

Equipment

Read more on CISA Alerts