OpenPLC v3

Summary

A critical vulnerability, CVE-2026-14480, has been identified in OpenPLC v3, allowing authenticated attackers to write arbitrary files to the filesystem. This could lead to arbitrary native code execution by exploiting the normal OpenPLC program compilation process.

IFF Assessment

FOE

The vulnerability allows for arbitrary code execution, posing a direct threat to the integrity and availability of critical infrastructure systems running OpenPLC.

Severity

9.9 Critical

Defender Context

This vulnerability in OpenPLC v3 poses a significant risk to critical infrastructure sectors like manufacturing and energy. Defenders must prioritize patching or upgrading to OpenPLC v4 and implement strict access controls to prevent unauthorized file writes and code execution.

Read Full Story →