Cyber Resilience
← All news
Confirmed

OpenPLC Runtime v3

Our takeCISA reports active exploitation in OpenPLC Runtime v3 (CVE-2026-88020). Session-cookie hijack lets attackers issue commands as an operator and seize control of the PLC and its physical processes. Patch immediately if you run it.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of CVE-2026-88020 in OpenPLC Runtime v3, allowing session cookie hijacking that leads to PLC control and physical process manipulation. Update to a fixed version immediately and isolate engineering workstations from untrusted networks.
What this means for you — Lean IT orgs:CISA reports active exploitation of a flaw in OpenPLC Runtime v3 that lets attackers take over the programmable logic controller. Update to the latest version right away and keep the system off the public internet.
What this means for you — MSP:CISA reports active exploitation of CVE-2026-88020 in OpenPLC Runtime v3, enabling session hijacking and unauthorized PLC control. Check every client running OpenPLC v3, apply the vendor fix on an emergency basis, and confirm OT network segmentation.
What this means for you — Researcher:CISA reports active exploitation of CVE-2026-88020 in OpenPLC Runtime v3, enabling session cookie hijacking that leads to full PLC and physical process control. Review affected environments and prioritize patching where this runtime is deployed.