CVE-2026-28205Disclosure(openplcproject / openplc_v3)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for openplcproject openplc_v3 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1188

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openplc_v3
  • openplc_v3_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-09); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
openplc_v3openplc_v3_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-11: 1Exploit Tool / Code · 2026-04-11: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 1Technical Details · 2026-04-11: 104-0904-1004-11
Signal classification2 categories
Disclosure
375.0%
Exploit
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-04-101
Disclosure1
2026-04-111
Exploit1
Full discourse4 posts
  • Shriyans Sudhi@ss0x00
    Exploit

    Got a few CVEs during a random past-midnight code audit: CVE-2026-28205, CVE-2026-35556 CISA Advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-10 Technical details with exploitation steps: https://ss0x00.com/research #infosec #cve

    Post summary

    The author identified CVE-2026-28205 and CVE-2026-35556, linked a CISA advisory and a page with detailed exploitation steps, indicating PoC/exploit availability but no evidence of active attacks.

    0000099
    495 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-28205: Initialization of a resource wit... OpenPLC_V3's insecure API defaults hand attackers network-accessible auth bypass with CVSS 9.2 - industrial control sys... https://zerodaysignal.com/vulnerability/CVE-2026-28205 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-28205 exposes a high‑severity authentication bypass via OpenPLC_V3’s insecure API, with a CVSS score of 9.2.

    0000060
    204 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28205 OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypas… https://www.cve.org/CVERecord?id=CVE-2026-28205 ----- Traducción: CVE-2026-28205 Ope… http://infoflow.cloud`

    Post summary

    The tweet cites CVE-2026-28205, detailing an insecure default initialization issue in OpenPLC_V3 that could enable unauthorized access, but offers no proof‑of‑concept, exploit, or patch information.

    0000026
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28205 OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypas… https://www.cve.org/CVERecord?id=CVE-2026-28205

    Post summary

    The post announces CVE‑2026‑28205 affecting OpenPLC_V3, describing an insecure default initialization that could expose the system to unauthorized access, and links to the official CVE record.

    00000122
    57.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWopenplcprojectopenplc_v3---
OSopenplcprojectopenplc_v3_firmware---

Explore more