Safeguard
Vulnerability Analysis

Two 2021 ScadaBR Bugs Take Four Years to Reach Confirmed Exploitation

An unrestricted JSP upload and a stored XSS bug in OpenPLC's ScadaBR, both disclosed the same day in 2021, were confirmed exploited within a week of each other in late 2025.

Safeguard Research Team
5 min read

OpenPLC's ScadaBR component had two vulnerabilities confirmed exploited and added to CISA's KEV catalogue within a week of each other in late 2025, both originally disclosed more than four years earlier in 2021 — an unrestricted file upload bug that lets an authenticated user execute arbitrary JSP files, and a stored cross-site scripting flaw in the system settings page.

CVECVSSFlawAdded to KEV
CVE-2021-268288.8Unrestricted JSP file upload via view_edit.shtm3 Dec 2025
CVE-2021-268295.4Stored XSS via system_settings.shtm28 Nov 2025

A four-year gap between disclosure and confirmed exploitation is the headline, not the CVSS score

Both of these vulnerabilities were originally published to NVD on 11 June 2021 — the same day, in fact, with sequential CVE numbers — and both sat unconfirmed as actively exploited for roughly four and a half years before CISA added them to KEV within days of each other in late November and early December 2025. That gap matters more than either individual CVSS score, because it tells defenders something specific about the population still running exposed ScadaBR: these are systems that never applied a fix that has existed since 2021, and they were specifically found and exploited only recently, likely as part of a broader sweep of internet-reachable SCADA and industrial monitoring software rather than a targeted campaign against a single organization. NVD's notes on both CVEs flag that the vulnerability "could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products," which widens the exposed population beyond organizations that specifically chose OpenPLC's ScadaBR distribution to include anyone running derivative or forked SCADA-LTS-based software carrying the same unpatched upload and sanitization logic.

Why the pairing of an upload bug and an XSS bug in the same product describes a full compromise chain

CVE-2021-26828 alone is a remote authenticated attacker's path to full code execution: uploading and executing an arbitrary JSP file via view_edit.shtm hands the attacker a webshell on the underlying server, at a CVSS of 8.8 that reflects high impact across confidentiality, integrity, and availability. CVE-2021-26829's stored XSS in system_settings.shtm is lower severity in isolation but supplies exactly the kind of session-hijacking or credential-harvesting foothold that turns an unauthenticated attacker into the authenticated one CVE-2021-26828 requires. A researcher's video demonstration referenced in the NVD entry for CVE-2021-26829, alongside a public forum disclosure thread covering both bugs together, suggests these were documented and understood as a related pair from the start rather than independently discovered years apart — which makes their near-simultaneous appearance in KEV four years later look less like coincidence and more like both halves of the same known attack path finally being observed in the wild together.

SCADA and industrial monitoring software carries exposure most enterprise software doesn't

ScadaBR functions as a supervisory control and data acquisition (SCADA) human-machine interface, a category of software that historically sits closer to physical processes — building management, utility monitoring, industrial equipment — than typical enterprise IT does, and one where legacy deployments often run for years without the patch cadence applied to standard web applications. A 2025 blog post referenced in CVE-2021-26829's NVD references, describing "anatomy of a hacktivist attack" targeting Russian-aligned groups against OT/ICS infrastructure, underscores that these older SCADA-adjacent bugs remain live tools for ideologically motivated attackers specifically because so much of this software class runs unpatched and internet-reachable for years past its disclosure date.

What to check this week

Identify every ScadaBR instance and any SCADA-LTS-derived fork in the environment, given NVD's explicit note that this same underlying flaw could be present in other products built on shared components — a straightforward version check against the named product alone may miss derivative installations.

Patch or upgrade past ScadaBR 1.12.4 (Windows) and 0.9.1 (Linux), the versions both advisories identify as vulnerable, prioritizing CVE-2021-26828 given its 8.8 severity and direct path to remote code execution.

Remove any unnecessary internet exposure of SCADA/HMI interfaces entirely, since software in this category is rarely intended to be reachable from the open internet in the first place, and network segmentation closes both of these findings simultaneously regardless of patch status.

Treat any four-plus-year-old disclosure that newly enters KEV as evidence of active scanning for that specific vulnerability, since a bug's sudden appearance in confirmed exploitation long after its original disclosure date typically signals an attacker group actively sweeping for exactly that unpatched population.

A closing note on legacy OT and SCADA exposure

The four-year gap here isn't unusual for industrial and SCADA-adjacent software specifically — this category of system is disproportionately represented among old, unpatched, internet-reachable KEV entries precisely because it sits outside the normal enterprise patch management lifecycle that catches conventional IT software faster.

How Safeguard helps

Safeguard's continuous inventory extends to SCADA, HMI, and industrial monitoring software alongside conventional IT assets, surfacing legacy components like ScadaBR — and its derivatives — that would otherwise sit outside a typical enterprise patch cycle for years until, as here, they resurface as confirmed exploitation targets.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.