CISA added CVE-2021-26829 to its Known Exploited Vulnerabilities list after confirmed attacks against OpenPLC ScadaBR systems. The flaw allows stored cross site scripting on the system_settings.shtm page where malicious script runs every time an operator loads the interface. Forescout observed a pro Russian hacktivist group abusing the bug on an ICS honeypot that mimicked a water treatment plant. The attackers used default credentials, altered the HMI view, and tampered with logs and alarms.
Relevant Source (SecurityWeek): CISA Warns of ScadaBR Vulnerability After Hacktivist ICS Attack
This article explains that CISA added CVE-2021-26829 in OpenPLC ScadaBR to its Known Exploited Vulnerabilities catalog after a pro-Russian hacktivist group used the stored XSS flaw against a water treatment ICS honeypot, aligning with the attacks described in this section.
Quick Facts
- CISA confirmed active exploitation of CVE-2021-26829 in ScadaBR
- The flaw affects Windows and Linux builds
- Attackers can plant persistent script in system_settings.shtm
- Forescout saw real attacks against a water treatment honeypot
- Many small utilities run outdated ScadaBR with weak security
- Default credentials and open remote desktop paths widen exposure
How CVE-2021-26829 Lets Attackers Hijack ScadaBR
CVE-2021-26829 is a stored cross site scripting flaw inside the system_settings.shtm page of OpenPLC ScadaBR. The vulnerability lets an attacker inject script that executes every time an operator loads the page, which turns a routine settings check into a foothold for deeper manipulation. It affects both Windows and Linux deployments, including older builds that commonly sit on poorly secured utility networks.
- Injects persistent script into the settings page
- Executes automatically when operators load the HMI
- Enables tampering with logs, alarms, and displayed values
Small utilities that still rely on legacy ScadaBR installations face elevated risk because many systems run with reused passwords and weak isolation.
Relevant Source (NIST NVD): CVE-2021-26829 Detail
This entry confirms that OpenPLC ScadaBR on both Linux and Windows suffers from a stored XSS vulnerability in system_settings.shtm, matching the persistent script injection and operator page execution described in this section.
Why Active ScadaBR Exploits Threaten Small Utilities
CISA added the vulnerability to the KEV list because attackers have moved from probing to active exploitation. Forescout watched a pro-Russian group log into an ICS honeypot using default credentials, then trigger the flaw to deface the interface and manipulate operational data. This pattern mirrors real field conditions where small town utilities run ScadaBR on aging workstations that double as normal PCs.
- Attackers gain code execution inside the operator’s browser
- Local access can pivot into deeper system control
- HMI manipulation can mask alarms or inject false readings
- Flat networks allow movement beyond the SCADA host
- Default passwords and open services make compromise easier
Utilities with limited security staffing face the greatest impact because these systems often sit exposed without formal patching schedules or network segmentation.
Relevant Source (LinuxSecurity.com): CISA Adds Actively Exploited ScadaBR XSS Bug to KEV, Raising Linux Security Concerns
This article explains that CISA added OpenPLC ScadaBR CVE-2021-26829 to its Known Exploited Vulnerabilities catalog after confirmed exploitation of the stored XSS flaw in real environments.
Mitigating ScadaBR KEV Risk For Small Utilities
Small operators can shrink exposure by tightening basic access controls and reviewing where ScadaBR is deployed. Start with version checks, access paths, and credential hygiene, then escalate to network restrictions.
Steps to follow:
- Confirm ScadaBR version and check vendor guidance
- Scan for exposed system_settings.shtm paths
- Replace default or shared credentials immediately
- Restrict HMI access to VPN users only
- Remove direct internet exposure and disable open RDP
- Plan upgrades or migration away from unsupported builds
A short conversation with your integrator or vendor can help determine realistic timelines for patching or replacing aging systems.
Relevant Source (Daily Security Review): CISA Updates KEV Catalog To Include OpenPLC ScadaBR Vulnerability
This article details CISA’s addition of CVE-2021-26829 to the KEV catalog and outlines mitigation steps like patching, monitoring, and reviewing ICS security posture, which aligns with the remediation workflow in this section.
Legacy SCADA Weaknesses Put Utilities At Cyber Risk
CVE-2021-26829 highlights a growing problem in industrial environments where legacy software and casual admin practices create exploitable seams. Many small utilities depend on hardware and software that were never designed for modern threat pressure, which leaves them vulnerable even when the underlying flaw is old. Attackers understand that a weak SCADA workstation offers a quick path to operational impact.
This incident reinforces that default passwords, open network paths, and outdated HMIs amplify the damage potential of flaws that might otherwise be containable. As long as industrial networks keep flat layouts and expose browser based interfaces, attackers will continue targeting them with low effort tactics.
Relevant Source (CISA): Internet Exposed HMIs Pose Cybersecurity Risks To Water And Wastewater Systems
This fact sheet describes how internet exposed HMIs, default passwords, and flat networks at water utilities create operational risk that mirrors the legacy SCADA weaknesses summarized in this section.
Treat CVE-2021-26829 As A Wake Up Call
Utilities running ScadaBR should treat this vulnerability as a signal to review their security posture. Tightening credential policies, isolating HMIs, and confirming software versions can cut off the simplest attack paths. A few hours of review and cleanup often prevent situations where attackers alter logs or mislead operators.
Relevant Source (Industrial Cyber): OpenPLC ScadaBR Added To CISA’s Known Exploited List After Confirmed Attacks
This article describes how confirmed real world exploitation of CVE-2021-26829 led CISA to add ScadaBR to its KEV catalog and urges asset owners to review, harden, and update affected deployments, which aligns with the conclusion’s call to reassess security posture.
FAQ
Is ScadaBR still vulnerable if it runs on Linux?
Yes. The flaw affects Windows and Linux builds because it lives in the web interface code.
How do attackers exploit the bug?
They inject script into the settings page and wait for an operator to load it, which triggers execution.
Does patching eliminate the stored script?
Patching stops new injections but you must remove any existing malicious entries manually.
Do default credentials matter for this attack?
Yes. Most observed intrusions started with attackers logging in using default or reused passwords.
Should ScadaBR be exposed to the internet?
No. Place it behind a VPN or segmented network to block direct access.
How JENI Helps Strengthen System Stability
JENI supports environments where older SCADA workstations and shared utility PCs often carry extra risk. These machines handle heavy workloads, run outdated software, and sometimes accumulate system errors that weaken their overall reliability. A cleaner, healthier operating system reduces the chance that basic performance issues turn into operational blind spots.
What JENI Improves:
- Cleans out cluttered system data that slows or destabilizes SCADA hosts
- Repairs underlying Windows or macOS issues that affect reliability
- Helps keep operator workstations stable during continuous monitoring
A well maintained system gives operators a clearer view of what is happening on the network. Stable machines handle logs, alerts, and browser based HMIs with fewer crashes or delays. Reduced system noise makes it easier to notice abnormal behavior that could signal intrusion. Sound workstation hygiene supports security teams by removing technical friction that often hides early warning signs.

