CVE-2025-1066: OpenPLC

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campaigns.

Affected products

Published 2025-02-06. Last modified 2026-06-17.