CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

OpenPLC v3

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2262

As cited

Copy frozen at (site build).

vulnerabilities

OpenPLC v3

A critical vulnerability (CVE-2026-14480) in OpenPLC v3 allows authenticated attackers to write arbitrary files to the filesystem and achieve native code execution by injecting malicious C++ files into the runtime core directory. The flaw exists in the legacy web UI program-upload workflow, where user-supplied filenames are stored without validation and later used as destination paths. OpenPLC v3 is end-of-life and will not receive patches, with the vendor recommending users upgrade to OpenPLC v4.

Why it matters: Organizations running OpenPLC v3 in critical manufacturing, energy, transportation, or water systems worldwide must upgrade immediately to v4, as authenticated insiders or compromised accounts can execute arbitrary code at the runtime process privilege level.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

OpenPLC v3

A critical vulnerability (CVE-2026-14480) in OpenPLC v3 allows authenticated attackers to write arbitrary files to the filesystem and achieve native code execution by injecting malicious C++ files into the runtime core directory. The flaw exists in the legacy web UI program-upload workflow, where user-supplied filenames are stored without validation and later used as destination paths. OpenPLC v3 is end-of-life and will not receive patches, with the vendor recommending users upgrade to OpenPLC v4.

Why it matters: Organizations running OpenPLC v3 in critical manufacturing, energy, transportation, or water systems worldwide must upgrade immediately to v4, as authenticated insiders or compromised accounts can execute arbitrary code at the runtime process privilege level.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary