Back to signals
CISA advisoryVulnerabilitiesPublished September 22, 2026

OpenPLC Runtime v3

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives. The following versions of OpenPLC Runtime v3 are affected: OpenPLC 3 (CVE-2026-88020) CVSS Vendor Equipment Vulnerabilities v3 6.1 Autonomy Logic OpenPLC Runtime v3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-88020 The affected product is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding. View CVE Details Affected Products OpenPLC Runtime v3 Vendor: Autonomy Logic Product Version: Autonomy Logic OpenPLC: 3 Product Status: known_affected Remediations Vendor fix Autonomy Log…

Open the source record
Tags
CISA
Related exam domains
CISM 2: Information Security Risk Management; CISM 3: Information Security Program
Source record id
/node/25529
First seen by InfoSec Signals
9/23/2026

Exam domain labels come from a keyword heuristic and are study hints, not an official mapping. The summary is the publisher's own text, shortened; the linked record is authoritative.