Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogindustrial-control-system-vulnerabilitydefault-credential-exposure

Active Exploitation of OpenPLC ScadaBR XSS Vulnerability CVE-2021-26829

Updated 3mo agoFirst seen Nov 30, 20253 sources

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2021-26829, a cross-site scripting (XSS) vulnerability in OpenPLC ScadaBR, to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation. This flaw affects OpenPLC ScadaBR through version 1.12.4 on Windows and 0.9.1 on Linux, specifically via the system_settings.shtm component. The vulnerability allows attackers to manipulate the HMI login page and system settings, potentially disabling logs and alarms, which could have significant operational impacts on industrial control systems.

Recent reports indicate that the pro-Russian hacktivist group TwoNet exploited this vulnerability against a honeypot mimicking a water treatment facility. The attackers gained initial access using default credentials, established persistence by creating a new user account, and then leveraged CVE-2021-26829 to deface the HMI interface and disrupt system monitoring. CISA's alert underscores the ongoing risk to industrial environments and the need for immediate remediation of affected OpenPLC ScadaBR installations.

Share:
Active Exploitation of OpenPLC ScadaBR XSS Vulnerability CVE-2021-26829
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Dec 19, 20256mo ago

CISA sets federal remediation deadline for CVE-2021-26829

CISA required Federal Civilian Executive Branch agencies to remediate CVE-2021-26829 under Binding Operational Directive 22-01. The deadline set for agencies was December 19, 2025.

Nov 30, 20257mo ago

VulnCheck links cloud-hosted OAST infrastructure to broad exploit activity

Reporting published on November 30, 2025 described a long-running Google Cloud-hosted OAST endpoint apparently supporting a Brazil-focused exploit operation, with roughly 1,400 exploit attempts across more than 200 CVEs. VulnCheck linked the infrastructure to detectors-testing[.]com patterns and a Java class extending a public Fastjson RCE exploit for command execution and outbound callbacks.

Nov 29, 20257mo ago

CISA adds OpenPLC ScadaBR flaw CVE-2021-26829 to the KEV catalog

On November 29, 2025, CISA added CVE-2021-26829, a cross-site scripting flaw affecting OpenPLC ScadaBR, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The vulnerability affects OpenPLC ScadaBR versions through 1.12.4 on Windows and through 0.9.1 on Linux.

Sep 1, 202510mo ago

TwoNet attacks ICS honeypot using default credentials and CVE-2021-26829

In September 2025, Forescout observed the pro-Russian hacktivist group TwoNet target an ICS/OT honeypot posing as a water treatment facility. The attackers used default credentials for initial access, created persistence, then exploited CVE-2021-26829 to deface the HMI and disable logs and alarms.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Threat actors
3 linked
Organizations
10 linked
CISAForescoutTwoNetCyberTroopsOverFlameOpenPLC ScadaBRSecurity AffairsFederal Civilian Executive BranchVulnCheckGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.