Our takeCISA reports active exploitation in OpenPLC Runtime v3 (CVE-2026-88020). Session cookie hijack lets attackers issue commands as an operator and seize control of the PLC and its physical processes. Patch immediately if you run this.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA reports active exploitation of CVE-2026-88020 in OpenPLC Runtime v3; successful attacks let remote adversaries hijack operator sessions and issue commands that can alter PLC logic and physical processes. Update to a fixed version or isolate the runtime from untrusted networks immediately.
What this means for you — Lean IT orgs:If you run OpenPLC Runtime v3 on any equipment, update it right away or disconnect it from the internet — attackers are already using this flaw to take over the controllers and the machines they run.
What this means for you — MSP:Scan client environments for any use of OpenPLC Runtime v3; patch immediately or air-gap the affected instances, as CISA states it is under active exploitation that can give full control of PLC-driven physical processes.
What this means for you — Researcher:CISA advisory ICSA-26-265-09 confirms active exploitation of session-cookie hijacking (CVE-2026-88020) in OpenPLC Runtime v3 that leads to operator-level PLC command injection and physical process manipulation.