<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-88020 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-88020/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 17:46:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-88020/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored and Reflected XSS Vulnerability in OpenPLC Runtime v3</title><link>https://feed.craftedsignal.io/briefs/2026-09-openplc-runtime-xss/</link><pubDate>Tue, 22 Sep 2026 17:46:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-openplc-runtime-xss/</guid><description>OpenPLC Runtime v3 contains a cross-site scripting vulnerability that allows attackers to hijack operator session cookies and issue unauthorized commands to industrial control processes.</description><content:encoded><![CDATA[<p>OpenPLC Runtime v3, developed by Autonomy Logic, contains a vulnerability identified as CVE-2026-88020. The flaw stems from improper neutralization of input within the product's web interface, specifically when the application routes programs based on unencoded query string parameters. This cross-site scripting (XSS) vulnerability allows an attacker to inject malicious scripts into the web interface.</p>
<p>If a logged-in operator visits a crafted link or navigates to a compromised page, the attacker can hijack active session cookies. By gaining control of an operator's session, an attacker can issue state-changing requests, potentially manipulating the programmable logic controller (PLC) and disrupting the physical industrial processes it manages. OpenPLC Runtime v3 has reached end-of-life status and will not receive security patches; the vendor advises all users to upgrade to OpenPLC v4 to remediate this issue.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects critical infrastructure sectors including energy, water, manufacturing, and transportation systems globally. Successful exploitation allows for session hijacking, enabling unauthorized control over physical industrial processes. If exploited, an attacker could potentially override safety logic or disrupt operational technology (OT) services, leading to physical damage or process outages.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security operations and IT teams:</p>
<ul>
<li>Immediately migrate from OpenPLC v3 to OpenPLC v4, as v3 is end-of-life and will not be patched for CVE-2026-88020.</li>
<li>Isolate all OpenPLC web interfaces from public internet access by placing them behind firewalls or utilizing VPNs for remote management.</li>
<li>Implement strict network segmentation to ensure control system devices are not reachable from business or guest networks.</li>
<li>Conduct an audit of existing industrial control system (ICS) exposure to identify and block unauthorized access to web-based management consoles.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>xss</category><category>ics</category><category>cve-2026-88020</category><category>critical-infrastructure</category></item></channel></rss>