CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog to include CVE-2021-26829, a cross-site scripting (XSS) vulnerability affecting OpenPLC ScadaBR. This vulnerability allows attackers to exploit the system_settings.shtm component, posing a significant risk to organizations using this product. The update was reflected in both the official KEV data repository and a public CISA advisory, which highlights the active exploitation of this flaw and the need for immediate mitigation.
Federal Civilian Executive Branch (FCEB) agencies are required by Binding Operational Directive (BOD) 22-01 to remediate this vulnerability by the specified due date. CISA also strongly encourages all organizations, not just federal agencies, to prioritize remediation of vulnerabilities listed in the KEV Catalog to reduce exposure to cyberattacks. The advisory provides references for further technical details and mitigation guidance, emphasizing the ongoing threat posed by known exploited vulnerabilities in widely used industrial control systems.

See which actors are running it and whether you're in range.
1 event from the most recent confirmed update back to the earliest known activity.
CISA announced that it added CVE-2021-26829, an OpenPLC ScadaBR cross-site scripting vulnerability, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The agency said the flaw poses significant risk to the federal enterprise and is subject to remediation requirements under Binding Operational Directive 22-01 for FCEB agencies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.