CVE-2026-14480Disclosure

MEDIUMCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database field and later uses this value as the destination path for an uploaded file without validating or restricting the path. Because Python os.path.join() honors attacker‑controlled absolute paths, an authenticated user can write arbitrary files anywhere writable by the OpenPLC webserver process. In the default build pipeline, all C++ source files within the OpenPLC runtime core directory are automatically compiled into the executable runtime binary. By writing a malicious .cpp file into this directory, an authenticated attacker can escalate the arbitrary file write into arbitrary native code execution when the operator triggers a normal program compilation and runtime start.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-07-09); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-09: 1Mentions · 2026-07-12: 1Mentions · 2026-08-14: 1Active Exploitation · 2026-07-09: 1Patch / Workaround · 2026-07-12: 1Technical Details · 2026-07-12: 1Technical Details · 2026-08-14: 107-0907-1208-14
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-091
Active Exploitation1
2026-07-121
Disclosure1
2026-08-141
Disclosure1
Full discourse3 posts
  • Professor Simon@ProfSimonOnline
    Disclosure

    Did you know CISA recently flagged a critical flaw in OpenPLC Runtime (CVE-2026-14480) with a CVSS score of 9.9? This could significantly impact industrial control environments, making ongoing vigilance essential. Stay updated on your systems.

    Post summary

    CISA has flagged a critical flaw in OpenPLC Runtime (CVE‑2026‑14480) with a CVSS score of 9.9, urging vigilance but providing no evidence of exploitation or remediation.

    0001041
    55 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-14480 in OpenPLC v3 systems to write malicious files and escalate privileges. Following compromise, they moved laterally within industrial networks to disrupt control processes. Runtime segmentation helps contain such post-compromise activity across OT environments. #ZeroDay #CloudSecurity :link: Full breakdown: https://aviatrix.ai/threat-research-center/openplc-v3-cve-2026-14480

    Post summary

    The tweet reports that CVE-2026-14480 is being actively exploited in OpenPLC v3 systems, enabling attackers to write malicious files, privilege‑escalate, and move laterally to disrupt industrial control processes.

    00100171
    1.9K followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    #CRITICAL CVE-2026-14480: OpenPLC Runtime v3 authenticated arbitrary file write (CVSS 9.9) allows code execution via malicious .cpp upload. Authenticated attackers can write files anywhere writable by webserver. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/VByWTxlkgB

    Post summary

    A critical vulnerability (CVSS 9.9) in OpenPLC Runtime v3 allows authenticated attackers to execute code via malicious .cpp uploads; an urgent patch is required.

    0000049
    71 followersView on X

Explore more