Cyber Resilience
← All news
Confirmed

OpenPLC Runtime v3

Our takeCISA reports active exploitation in OpenPLC Runtime v3 (CVE-2026-88020). Session cookie hijack lets attackers issue commands as an operator and seize control of the PLC and its physical processes. Patch immediately if you run this.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of CVE-2026-88020 in OpenPLC Runtime v3; successful attacks let remote adversaries hijack operator sessions and issue commands that can alter PLC logic and physical processes. Update to a fixed version or isolate the runtime from untrusted networks immediately.
What this means for you — Lean IT orgs:If you run OpenPLC Runtime v3 on any equipment, update it right away or disconnect it from the internet — attackers are already using this flaw to take over the controllers and the machines they run.
What this means for you — MSP:Scan client environments for any use of OpenPLC Runtime v3; patch immediately or air-gap the affected instances, as CISA states it is under active exploitation that can give full control of PLC-driven physical processes.
What this means for you — Researcher:CISA advisory ICSA-26-265-09 confirms active exploitation of session-cookie hijacking (CVE-2026-88020) in OpenPLC Runtime v3 that leads to operator-level PLC command injection and physical process manipulation.