#CVE2026102508
A critical Apache PLC4X vulnerability, CVE-2026-102508, lets attackers impersonate OPC UA servers and steal credentials. Upgrade to PLC4X 1.0.0 now.

#Apache="/hashtag/ApachePLC4X" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#ApachePLC4X #PLCref="/hashtag/PLC4X" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#PLC4X #OPCUA #CVE2026102508 #ICSSecurity #OTSecurity #PLC #Apache
Critical Apache PLC4X Flaw Lets Attackers Hijack OPC UA Connections to PLCs
TL;DR The Apache Software Foundation disclosed CVE-2026-102508, a critical Apache PLC4X vulnerability in its OPC UA driver, on September 30, 2026. It scores 9.2 under CVSS 4.0. An attacker in a network position between client and server can impersonate the server and steal user credentials. Why This Apache PLC4X Vulnerability Matters Apache PLC4X is a set of libraries for talking to industrial programmable logic controllers (PLCs).
securityonline.info
September 30, 2026 at 8:44 AM