The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2021-26829, a cross-site scripting (XSS) vulnerability in OpenPLC ScadaBR, to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation. This flaw affects OpenPLC ScadaBR through version 1.12.4 on Windows and 0.9.1 on Linux, specifically via the system_settings.shtm component. The vulnerability allows attackers to manipulate the HMI login page and system settings, potentially disabling logs and alarms, which could have significant operational impacts on industrial control systems.
Recent reports indicate that the pro-Russian hacktivist group TwoNet exploited this vulnerability against a honeypot mimicking a water treatment facility. The attackers gained initial access using default credentials, established persistence by creating a new user account, and then leveraged CVE-2021-26829 to deface the HMI interface and disrupt system monitoring. CISA's alert underscores the ongoing risk to industrial environments and the need for immediate remediation of affected OpenPLC ScadaBR installations.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
CISA required Federal Civilian Executive Branch agencies to remediate CVE-2021-26829 under Binding Operational Directive 22-01. The deadline set for agencies was December 19, 2025.
Reporting published on November 30, 2025 described a long-running Google Cloud-hosted OAST endpoint apparently supporting a Brazil-focused exploit operation, with roughly 1,400 exploit attempts across more than 200 CVEs. VulnCheck linked the infrastructure to detectors-testing[.]com patterns and a Java class extending a public Fastjson RCE exploit for command execution and outbound callbacks.
On November 29, 2025, CISA added CVE-2021-26829, a cross-site scripting flaw affecting OpenPLC ScadaBR, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The vulnerability affects OpenPLC ScadaBR versions through 1.12.4 on Windows and through 0.9.1 on Linux.
In September 2025, Forescout observed the pro-Russian hacktivist group TwoNet target an ICS/OT honeypot posing as a water treatment facility. The attackers used default credentials for initial access, created persistence, then exploited CVE-2021-26829 to deface the HMI and disable logs and alarms.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.