LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-26829: OpenPLC ScadaBR Cross-site Scripting Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 28, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 19, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-26829 to its Known Exploited Vulnerabilities catalog on Nov 28, 2025, with a federal patch deadline of Dec 19, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.

CVE-2021-26829 is a cross-site scripting vulnerability in OpenPLC ScadaBR that can be triggered through the system_settings.shtm component. Cross-site scripting flaws of this class allow an attacker to inject malicious scripts that execute in the browser of a user who interacts with the affected interface. For industrial control and SCADA environments that rely on OpenPLC ScadaBR, successful abuse can lead to session hijacking, unauthorized configuration changes, or further compromise of operator workstations, which is why defenders should treat it as a priority for inventory and remediation.

CISA notes that the required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for any cloud-hosted instances, or discontinue use of the product if mitigations are unavailable. Ransomware use associated with this CVE is not documented.

How it works

The vulnerability is classified as CWE-79, improper neutralization of input during web page generation (cross-site scripting). In products of this class, user-controlled data reaches a web page without adequate encoding or validation. An attacker who can supply input that is later rendered by system_settings.shtm can cause a victim’s browser to execute attacker-controlled script in the security context of the OpenPLC ScadaBR application.

Typical abuse patterns for this weakness involve crafting a request or link that places the payload into a parameter or form field processed by the vulnerable page. When an authenticated operator or administrator loads the resulting page, the script runs with the privileges of that user’s session. Exact request formats, parameters, and authentication requirements must be confirmed against the vendor advisory; public detail beyond the CISA summary is limited.

Am I affected? How to find it in your systems

OpenPLC ScadaBR is commonly deployed as a web-based SCADA/HMI interface for monitoring and controlling industrial processes, often on dedicated servers, engineering workstations, or virtual machines inside operational technology networks. Inventory efforts should focus on any host running OpenPLC ScadaBR, especially those exposing a web management interface.

Because configuration and exposure details vary, treat any unpatched instance as potentially vulnerable until the vendor advisory is reviewed.

How to remediate

The primary remediation is to apply the vendor-supplied update or mitigation instructions for OpenPLC ScadaBR. Confirm the precise package, version, or configuration change against the official vendor advisory before deployment. After patching, verify that the system_settings.shtm page no longer accepts or reflects untrusted input without proper encoding.

Hardening steps common to this class of web application include enforcing strict output encoding, implementing a content-security policy, and restricting administrative access to trusted networks only.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to SCADA and web-management interfaces.

These measures lower risk but do not eliminate the underlying flaw; schedule permanent remediation as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities can lead to unauthorized access and data exposure even when ransomware use is not documented for a specific CVE. Review logs for signs of successful script injection or subsequent lateral movement, rotate any credentials that may have been handled through the ScadaBR interface, and assess whether process or configuration data could have been viewed or altered. You can run a free exposure scan of your email addresses against known breach data sets to determine whether related accounts appear in public breach corpora, then take appropriate credential-reset and monitoring steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOpenPLC · ScadaBR
WeaknessCWE-79
Added to CISA KEVNov 28, 2025
Federal patch deadlineDec 19, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities