Mmastodon TechnologyCybersecurity first seen 13 h ago, last 13 h ago, peak #6
Critical Apache PLC4X vulnerability CVE-2026-102508 disclosed
Original: 🚨 CVE-2026-102508 — CVSS 9.2 CRITICAL Improper Verification of Cryptographic Signature and Improper Certificate Validati
A critical vulnerability, CVE-2026-102508 with a CVSS score of 9.2, has been disclosed in the OPC UA driver of Apache PLC4X (PLC4J). The flaw involves improper cryptographic signature verification and certificate validation, allowing a network attacker positioned between client and server to impersonate the OPC UA server. Security watchers are urging industrial users of the library to patch promptly.
Why now: A newly disclosed critical-severity flaw in widely used industrial automation software raises urgent security concerns.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/470712