SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-3869

CRITICAL · CVSS 9.2 EPSS 0.54%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A critical vulnerability exists in certain programmable logic controllers (PLCs) due to an incorrect implementation of the authentication algorithm, potentially compromising the confidentiality, integrity, and availability of the system. If an application project with a lower security level is executed on the affected PLC, it could allow unauthorized access and manipulation of the PLC's operations. Organizations utilizing these PLCs, particularly in industrial control systems, should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-3869
Severity
CRITICAL
CVSS
9.2
EPSS
0.54%

Original NVD Description

CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC.