CVE-2026-14480 is an authenticated arbitrary file write vulnerability in OpenPLC Runtime v3's legacy web UI program-upload workflow. The application stores an attacker-supplied filename directly into the Programs.File database field and later uses this value as the destination path for an uploaded file without validating or restricting the path. This vulnerability allows an authenticated user to write arb [truncated]
CVE-2021-26828 is an unrestricted upload of file with dangerous type vulnerability affecting OpenPLC ScadaBR. CISA has added it to the Known Exploited Vulnerabilities catalog, which means defenders should treat it as an urgent remediation item rather than a routine patch. If ScadaBR is exposed or reachable in production, prioritize mitigation immediately and follow CISA guidance if no effective mitigation [truncated]
CVE-2021-26829 is a cross-site scripting vulnerability in OpenPLC ScadaBR that CISA added to the Known Exploited Vulnerabilities (KEV) catalog. Because it is listed in KEV, defenders should treat it as actively important and prioritize vendor mitigations or alternative controls. The public source material provided here does not include affected version ranges or technical exploit details, so response shou [truncated]