View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives. The following versions of OpenPLC Runtime v3 are affected: OpenPLC 3 (CVE-2026-88020) CVSS Vendor Equipment Vulnerabilities v3 6.1 Autonomy Logic OpenPLC Runtime v3 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) Background Critical Infrastructure Sectors: Critical Manufacturing, Energ
OpenPLC Runtime v3
calendar_today
September 22, 2026
person
CISA
domain
cybersecurity-and-infrastructure-security-agency