
CODESYS targeting. CODESYS is the underlying runtime for hundreds of PLC brands. One vulnerability in CODESYS affects every PLC built on it. PIPEDREAM exploited CVE-2022-22986 and related flaws, a single capability reaching across dozens of vendors.
Post summary
The post reports that the PIPEDREAM threat actor has actively exploited CVE‑2022‑22986, a flaw in CODESYS that impacts all PLCs built on the platform, demonstrating real‑world use by attackers.
