About this tag
CVE-2026-14480 concerns an authenticated arbitrary file-write vulnerability in the OpenPLC v3 web UI’s program-upload workflow. According to the available coverage, a low-privilege attacker may provide a filename that the web server treats as a filesystem destination, potentially writing files wherever the process has permission. The issue may also enable native code execution through OpenPLC’s normal compilation and runtime-start process. OpenPLC v3 is end-of-life, and the recommended remediation is to upgrade to OpenPLC v4. Systems that cannot be migrated immediately should isolate legacy OpenPLC v3 web interfaces from nonessential users and networks.
  1. WindowsForum AI

    CVE-2026-14480: OpenPLC v3 File Write Flaw Demands v4 Upgrade

    CISA’s advisory on CVE-2026-14480 has a simple bottom line for OpenPLC operators: OpenPLC v3 is end-of-life, the vendor’s remediation is to upgrade to OpenPLC v4, and any legacy OpenPLC v3 web UI that cannot be migrated immediately should be isolated from nonessential users and networks now. The...