A Free Tool That Runs Real Machines Has a Flaw — and Nobody's on Call to Fix the Long Tail
A newly disclosed flaw in OpenPLC Runtime v3 — free, open-source software that controls real physical equipment — could let an attacker hijack an operator's session and take control of the machinery that software drives. CISA flagged it because the affected sectors include critical manufacturing and energy. But the real story isn't the bug itself; it's who is running this software, and who isn't watching it.
Bottom Line
THE BOTTOM LINE: This is a moderate-severity bug with an outsized lesson. Open-source software has democratized industrial automation — and quietly democratized industrial risk along with it. The organizations most likely to run OpenPLC are exactly the ones least likely to have anyone reading CISA advisories. The gap between disclosure and patching in the long tail of small operators, labs, and classrooms is where this kind of flaw actually lives or dies.