Autonomy Logic recommends upgrading to OpenPLC v4 as v3 is end-of-life. CISA recommends minimizing network exposure, placing control system devices behind firewalls, isolating from business networks, and using VPNs for remote access with current versions. No known public exploitation reported.
Quick answers
What is CVE-2026-88020?
Autonomy Logic recommends upgrading to OpenPLC v4 as v3 is end-of-life. CISA recommends minimizing network exposure, placing control system devices behind firewalls, isolating from business networks, and using VPNs for remote access with current versions. No known public exploitation reported.
How severe is CVE-2026-88020?
medium, CVSS 6.1
Is CVE-2026-88020 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-88020 be mitigated?
Autonomy Logic recommends upgrading to OpenPLC v4 as v3 is end-of-life. CISA recommends minimizing network exposure, placing control system devices behind firewalls, isolating from business networks, and using VPNs for remote access with current versions. No known public exploitation reported.
CVSS
6.1
Vendor
Autonomy Logic
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
OpenPLC Runtime v3
Mitigation
Autonomy Logic recommends upgrading to OpenPLC v4 as v3 is end-of-life. CISA recommends minimizing network exposure, placing control system devices behind firewalls, isolating from business networks, and using VPNs for remote access with current versions. No known public exploitation reported.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory regarding a Cross-site Scripting (XSS) vulnerability in Autonomy Logic OpenPLC Runtime v3. Successful exploitation could allow an attacker to hijack session cookies and issue state-changing requests as an operator, potentially enabling control of the programmable logic controller and the physical processes it drives. OpenPLC Runtime v3 is end-of-life; the vendor recommends upgrading to OpenPLC v4.