MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 13 h ago, last 13 h ago, peak #6

Critical Apache PLC4X vulnerability CVE-2026-102508 disclosed

Original: 🚨 CVE-2026-102508 — CVSS 9.2 CRITICAL Improper Verification of Cryptographic Signature and Improper Certificate Validati

A critical vulnerability, CVE-2026-102508 with a CVSS score of 9.2, has been disclosed in the OPC UA driver of Apache PLC4X (PLC4J). The flaw involves improper cryptographic signature verification and certificate validation, allowing a network attacker positioned between client and server to impersonate the OPC UA server. Security watchers are urging industrial users of the library to patch promptly.

Why now: A newly disclosed critical-severity flaw in widely used industrial automation software raises urgent security concerns.

Apache PLC4XPLC4JOPC UA

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/470712