The Hacker News
"CISA adds actively exploited XSS Bug CVE-2022-26829 in OpenPLC ScadaBR to KEV." Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents. Accessed on 30 November 2025, 1348 UTC. Content and Source: "The Hacker News." URL-- https://thehackernews.com/ Please check URL or scroll down to read your selections. Thanks for joining us today. Russ Roberts (https://www.hawaiicybersecurityjournal.net). CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV Nov 30, 2025 Hacktivism / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities ( KEV ) catalog to include a security flaw impacting OpenPLC ScadaBR, citing evidence of active exploitation. The vulnerability in question is CVE-2021-26829 (CVSS score: 5.4), a cross-site scripting (XSS) flaw that affects Windows and Linux versions of the software via system_settings.shtm. It impac...