#openplc
Odds of finding new old-stock of this control board - slim.

Lead time on a properly spec'd PLC replacement - 52weeks to never.

Lead time on an Arduino Uno running OpenPLC - couple hours.
March 25, 2026 at 2:41 PM
🛢️ openplc-editor 🛢️

IDE for creating programs for the OpenPLC Runtime

🔗 https://github.com/Autonomy-Logic/openplc-editor

#homebrew #newpkg #macos #cask
September 26, 2026 at 9:23 PM
Latest post from CISA
OpenPLC Runtime v3
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives. The following versions of OpenPLC Runtime v3 are affected: OpenPLC 3 (CVE-2026-88020) CVSS Vendor Equipment Vulnerabilities v3 6.1 Autonomy Logic OpenPLC Runtime v3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-88020 The affected product is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding. View CVE Details Affected Products OpenPLC Runtime v3 Vendor: Autonomy Logic Product Version: Autonomy Logic OpenPLC: 3 Product Status: known_affected Remediations Vendor fix Autonomy Logic recommends users upgrade to OpenPLC v4 as OpenPLC v3 is end-of-life and is no longer receiving patches, bug fixes, or security updates. Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N Acknowledgments Rajivarnan R. and Shirshak of Secnora reported this vulnerability to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification ) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-22 Date Revision Summary 2026-09-22 1 Initial Publication Legal Notice and Terms of Use
www.cisa.gov
September 22, 2026 at 3:37 PM
CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV thehackernews.com/2025/11/cisa...
CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV
CISA flags active exploitation of CVE-2021-26829 as TwoNet and OAST operations drive widespread scanning.
thehackernews.com
November 30, 2025 at 4:27 PM
OpenPLC Runtime lets intruders hijack session cookies to commandeer actual industrial hardware. Because who does not want strangers fiddling with plant machinery?

#PLCPanic #CookieMadness
September 22, 2026 at 5:21 PM
Using an Arduino Opta micro PLC, a few off-the-shelf components, and the popular OpenPLC software environment, automation control concepts can be built right on your own test bench.
Hands-On with the Arduino Opta Using OpenPLC - Technical Articles
Using an Arduino Opta PLC, a few off-the-shelf electrical components, and the popular OpenPLC software environment, automation control concepts can be built on your own test bench.
control.com
February 7, 2025 at 1:37 PM
OpenPLC v3

huntaegis.com
July 10, 2026 at 10:27 AM
Threat actors are now exploiting an XSS bug in the OpenPLC ScadaBR code editor, typically used for programming SCADA/PLC stuff

www.cisa.gov/news-events/...
CISA Adds One Known Exploited Vulnerability to Catalog | CISA
CISA has added one new vulnerability to its KEV Catalog, based on evidence of active exploitation.
www.cisa.gov
December 1, 2025 at 2:44 PM
🚨 EUVD-2026-84871
📊 5.3/10
🏢 Autonomy Logic

📝 Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface atte...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84871

#cybersecurity #infosec #cve #euvd
September 22, 2026 at 10:00 PM
Here we go again, as OpenPLC Runtime v3 treats session security like a novelty, leaving plant operators vulnerable to hijacked cookies. Intruders can casually seize operator privileges and fiddle with physical machinery, because why keep industrial equipment safe? Preventing this...

Read full story
September 22, 2026 at 5:21 PM
Critical RCE vulnerability found in OpenPLC
Critical RCE vulnerability found in OpenPLC - Security Affairs
Cisco’s Talos reported critical and high-severity flaws in OpenPLC that could lead to DoS condition and remote code execution.
buff.ly
September 30, 2024 at 9:42 AM
CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV
CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV
thehackernews.com
November 30, 2025 at 9:55 AM
STruC++ Unleashed: Why Autonomy-Logic’s New OPENPLC Compiler is a Game-Changer for Industrial Cyber Resilience + Video

Introduction: The convergence of information technology (IT) and operational technology (OT) has reached a critical inflection point. With the introduction of Autonomy-Logic’s new…
STruC++ Unleashed: Why Autonomy-Logic’s New OPENPLC Compiler is a Game-Changer for Industrial Cyber Resilience + Video
Introduction: The convergence of information technology (IT) and operational technology (OT) has reached a critical inflection point. With the introduction of Autonomy-Logic’s new OPENPLC compiler, STruC++, the barriers between traditional Structured Text (ST) programming and the power of C/C++ are dissolving. For cybersecurity professionals, this evolution is not just a software update; it represents a fundamental shift in the attack surface of industrial control systems (ICS), demanding a re-evaluation of how we secure programmable logic controllers (PLCs) in modern factory automation.
undercodetesting.com
March 8, 2026 at 2:46 PM
Y básicamente por ahora tiene un runtime de OpenPLC que estoy preparando para controlar la caldera de mi casa
April 30, 2025 at 8:47 AM
CISA added CVE-2021-26829, an actively exploited XSS bug in OpenPLC ScadaBR, to its KEV catalog. FCEB agencies must patch by Dec 19, 2025. TwoNet group used it in honeypot attack. #ICS #News
CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV
CISA added CVE-2021-26829, an actively exploited XSS bug in OpenPLC ScadaBR, to its KEV catalog. FCE...
thehackernews.com
December 1, 2025 at 12:07 AM
CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV thehackernews.com/2025/11/cisa...
CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV
CISA flags active exploitation of CVE-2021-26829 as TwoNet and OAST operations drive widespread scanning.
thehackernews.com
December 2, 2025 at 5:15 AM
OpenPLC Editor v405-beta: A Game-Changer for Industrial Automation & Cybersecurity

Introduction The latest release of OpenPLC Editor v4.0.5-beta introduces powerful features for Programmable Logic Controller (PLC) development, including IEC 61131-3 text formatting and enhanced device…
OpenPLC Editor v405-beta: A Game-Changer for Industrial Automation & Cybersecurity
Introduction The latest release of OpenPLC Editor v4.0.5-beta introduces powerful features for Programmable Logic Controller (PLC) development, including IEC 61131-3 text formatting and enhanced device configuration. As industrial automation increasingly integrates with IT and cybersecurity, understanding these tools is critical for securing Industrial Control Systems (ICS). Learning Objectives Understand OpenPLC’s new IEC 61131-3 text format for efficient variable management. Learn how to configure devices securely to prevent unauthorized access.
undercodetesting.com
August 16, 2025 at 12:15 PM
So this board actually does support ladder logic! You can program the Pi using OpenPLC (openplcproject.gitlab.io) and I set up the various drivers and whatnot so that you can read/write to the relays (DOUT) and Opto-isolators (DIN).
September 16, 2023 at 5:44 AM
Virtual PLCs Revolutionize Industrial Automation: Secure Your OT Environment with OpenPLC and CodeSys – A Cybersecurity Guide + Video

Introduction: Virtual PLCs (vPLC) replace traditional hardware controllers with software-based solutions, enabling seamless integration into Industry 4.0 and smart…
Virtual PLCs Revolutionize Industrial Automation: Secure Your OT Environment with OpenPLC and CodeSys – A Cybersecurity Guide + Video
Introduction: Virtual PLCs (vPLC) replace traditional hardware controllers with software-based solutions, enabling seamless integration into Industry 4.0 and smart manufacturing ecosystems. However, this digital transformation expands the attack surface, exposing operational technology (OT) to remote code execution, network sniffing, and API abuse. This article delivers actionable security hardening techniques for OpenPLC and CodeSys virtual PLCs, bridging software engineering best practices with OT cybersecurity.
undercodetesting.com
June 14, 2026 at 2:49 AM
OpenPLC and Industrial Control Systems: Mastering SCADA Security Through Open Source Automation + Video

Introduction: Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) environments form the backbone of critical infrastructure, yet they remain notoriously…
OpenPLC and Industrial Control Systems: Mastering SCADA Security Through Open Source Automation + Video
Introduction: Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) environments form the backbone of critical infrastructure, yet they remain notoriously vulnerable to cyber threats. OpenPLC, an open-source Programmable Logic Controller platform compliant with the IEC 61131-3 standard, offers a unique, risk-free environment for security professionals to dissect, attack, and defend industrial networks without jeopardizing live operations. Learning Objectives:
undercodetesting.com
March 21, 2026 at 8:42 PM
CISA warns of active exploitation of OpenPLC ScadaBR XSS vulnerability (CVE-2021-26829). Admins urged to apply patches immediately. #CyberSecurity #SCADA #Vulnerability #CISA Link: thedailytechfeed.com/cisa-warns-o...
November 30, 2025 at 3:42 PM
🔴 CVE-2026-14480 - Critical (9.9)

OpenPLC Runtime v3 contains an authenticated arbitrary file write
vulnerability in the legacy we...

https://www.thehackerwire.com/vulnerability/CVE-2026-14480/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
July 11, 2026 at 11:00 AM
I'm not familiar with Arduino or OpenPLC, but since it's a 16/16 AC in/out board, i'd try to remove that MCU, and connect new controller to the serial shift/parallel registers on the board, connected to inputs/outputs.
March 25, 2026 at 5:27 PM
CISA has added CVE-2021-26829, an OpenPLC/ScadaBR XSS vulnerability, to the Known Exploited Vulnerabilities Catalog.

XSS issues in operational technology systems continue to appear in real-world exploitation...

#CyberSecurity #Infosec #VulnerabilityManagement #ThreatIntel #PatchManagement
November 29, 2025 at 3:23 PM
Notícia da SecurityWeek

"CISA Warns of ScadaBR Vulnerability After Hacktivist ICS Attack" #bolhasec
CISA Warns of ScadaBR Vulnerability After Hacktivist ICS Attack
CISA warns of an old ‘OpenPLC ScadaBR’ flaw that was recently leveraged by hackers to deface what they believed to be an ICS.
www.securityweek.com
December 21, 2025 at 2:30 AM