ThreatsIndustrial & OTHighOpenPLC Runtime Stored XSS Flaw Enables Operator Session Hijacking and Unauthorized Physical Process Control CVE-2026-88020CISA warns of CVE-2026-88020 in OpenPLC Runtime v3 web interface, allowing attackers to hijack operator sessions and manipulate physical industrial processes.CST Newsroom·23 Sep 2026, 00:00 IST·15 min read