Skip to content
COOEY

EXPOSURES › CVE-2021-26828

CVE-2021-26828

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-12-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-26828 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

OpenPLC ScadaBR exposed arbitrary JSP execution

OpenPLC's ScadaBR allowed remote, authenticated users to upload and execute arbitrary JSP files, leading to potential remote code execution.

Shame score — OpenPLC ScadaBR's unrestricted file upload enabled remote code execution, a severe security flaw actively exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.