Skip to content

OpenPLC ScadaBR added to CISA's known exploited list after confirmed attacks

Industrialcyber.Co December 2, 2025

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds OpenPLC ScadaBR vulnerability to known exploited catalog after active exploitation evidence. The vulnerability, present in versions 0.9.1 on Linux and 1.12.4 on Windows, allows stored XSS via system_settings[dot]shtm, a common attack vector for malicious cyber actors, posing significant risks to federal systems.

Tracked under ‘CVE-2021-26829,’ CISA flagged the exploitation after confirming it is being actively exploited. Categorized as Medium and CVSS base score of 6.5, the vulnerability is a cross-site scripting vulnerability tied to system_settings.shtm and affects both Windows and Linux builds of the platform. It impacts OpenPLC ScadaBR through version 1.12.4 on Windows and through version 0.9.1 on Linux.

In October, Forescout researchers revealed that TwoNet hacktivists, a recent entrant to the pro-Russian hacktivist ecosystem, targeted a honeypot mimicking a water treatment plant in September 2025. The attack was claimed by TwoNet, a Russian-aligned group that has previously engaged in politically motivated cyber activity. Investigators found that the group gained access to the plant’s human-machine interface to deface systems, disrupt processes, manipulate operations, and attempt evasion tactics. They also identified Russian-linked IP addresses exploiting the HMI.

The team assessed with moderate confidence at the time that the actions from the exploited IPs were coordinated, evidenced by tight sequencing and complementary roles (initial access and web shell placement followed by extended HMI-level tampering). “The exploitation path (default credentials → CVE-2021-26828 → web shell) and subsequent HMI-only activity are consistent with low-to-moderate capability operators leveraging publicly available tooling.”

While Forescout couldn’t confirm whether the queries were generated by a tool or crafted manually, evidence suggests they were entered directly through the HMI web interface. “The attacker created a new user account named ‘BARLATI.’ The first login with this account took place at 3:20 PM – seven hours after the initial compromise. The last login occurred the following morning at 11:19 AM. During that window, the attacker carried out four defacement and disruption actions.”

The researchers disclosed that the exploited CVE-2021-26829 enabled the hackers to deface and change the HMI login page description triggering a pop-up alert with the expletive whenever the page was visited. The attack disrupted processes by deleting connected PLCs as data sources, cutting off real-time updates. It also manipulated operations by altering PLC setpoints through the HMI and evaded detection by changing system settings to disable logs and alarms.

Extracted Entities

Countries (1)

Platforms (2)

Vulnerabilities (2)