Brand
OpenPLC: actively exploited vulnerabilities
2 vulnerabilities in OpenPLC products (ScadaBR) are in CISA’s catalog of exploited vulnerabilities. Last added: December 3, 2025.
-
2 vulnerabilities added in the last 12 months
-
2 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one OpenPLC category to your radar, or open its page.
- Industrial and building systems 2 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- ScadaBR2 vulnerabilities, Industrial and building
Name used by CISA: OpenPLC. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this OpenPLC list.
- Rank 1
OpenPLC ScadaBRCVE-2021-26828
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
CVE from 2021, added in 2025
CVSS severity 8.8high
Added Dec 3, 2025
- Rank 2
OpenPLC ScadaBRCVE-2021-26829
OpenPLC ScadaBR Cross-site Scripting Vulnerability
CVE from 2021, added in 2025
CVSS severity 5.4medium
Added Nov 28, 2025
Follow and verify
Indicative classification, based on the vendor and product names given by CISA. How products are classified.