Vendor
critical
advisory
OpenPLC_v3 Heap-Based Buffer Overflow (CVE-2026-11826)
1 rule 2 TTPs 1 CVEAn authenticated attacker can exploit CVE-2026-11826, a heap-based buffer overflow in OpenPLC_v3's web interface, by sending a crafted HTTP POST request to the /modbus endpoint with an oversized device_name value, causing heap corruption, a runtime crash, and denial of service of the PLC process control loop, with no expected patch.
OpenPLC_v3
ics
ot
buffer-overflow
denial-of-service
cve
industrial-control-systems
1r
2t
1c
critical
advisory
OpenPLC v3 Arbitrary File Write Leads to Native Code Execution (CVE-2026-14480)
3 TTPsAn authenticated arbitrary file write vulnerability (CVE-2026-14480) in OpenPLC v3's legacy web UI program-upload workflow allows attackers to write arbitrary files, escalating to arbitrary native code execution as the OpenPLC runtime user when an operator triggers program compilation.
OpenPLC v3
ics
scada
vulnerability
rce
authenticated-rce
file-write
cwe-73
3t