2026-07-09NOTABLECISA ICS advisory: an authenticated file-write in OpenPLC's legacy web UI reaches native code execution, with no fixed version cited
OpenPLC v3 Runtime authenticated arbitrary file-write to native RCE (CVSS 9.9; CISA ICSA-26-190-01, no fix)
cve · CVE-2026-14480 single-source-national-cert
Coverage
1
first 2026-07-09 → last 2026-07-09
Latest activity
2026-07-09
CISA ICS advisory: an authenticated file-write in OpenPLC's legacy web UI reaches native code execution, with…
Peak priority
notable
1 notable
Targets
energy
sectors: energy, water, transport
Sources cited
1
1 hosts
Action items (3)
Do-now tasks recorded on the entries about CVE-2026-14480, newest first. Check the date before acting on an older one.
- Inventory OpenPLC v3 / OpenPLC Runtime deployments in OT and lab environments; ensure the web UI is never internet-reachable and is confined to an out-of-band management network, since no fixed version exists yet.2026-07-09CVE-2026-14480
- If the legacy web UI program-upload path is not required, disable/retire it; where web-UI authentication cannot be restricted to trusted operators only, treat the runtime as compromise-by-design until network isolation is enforced.2026-07-09CVE-2026-14480
- Hunt for new or modified .cpp files in the OpenPLC runtime core source directory outside maintainer deploys, and for the compiler toolchain (gcc/g++) being spawned by the OpenPLC webserver process rather than an operator-driven build.2026-07-09CVE-2026-14480
Defender insights
What each entry about CVE-2026-14480 tells a defender to do, newest first.
Triage
Story timeline
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-09/openplc-cve-2026-14480-file-write-rce · ATT&CK page ↗
Entries about OpenPLC v3 Runtime authenticated arbitrary file-write to native RCE (CVSS 9.9; CISA ICSA-26-190-01, no fix) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- OpenPLC×1
Where this entity is cited
Source distribution
- cisa.gov1 (100%)