<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: OpenPLC Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving OpenPLC.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:53 GMT</lastBuildDate><item><title>OpenPLC v3</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-190-01</link><guid isPermaLink="false">cst-2262</guid><description>A critical vulnerability (CVE-2026-14480) in OpenPLC v3 allows authenticated attackers to write arbitrary files to the filesystem and achieve native code execution by injecting malicious C++ files into the runtime core directory. The flaw exists in the legacy web UI program-upload workflow, where user-supplied filenames are stored without validation and later used as destination paths. OpenPLC v3 is end-of-life and will not receive patches, with the vendor recommending users upgrade to OpenPLC v4.</description><pubDate>Thu, 09 Jul 2026 12:00:00 GMT</pubDate></item></channel></rss>