Critical 9.8
CVE-2021-31886
Forescout Ports Pre-Auth RCE Exploit (CVE-2021-31886) Between WAGO PLC Models Using AI
Vendor / product: Siemens Nucleus FTP server, WAGO PLCs
Event date: 2026-09-01
Public PoC: Yes
First tracked by RiskWire: 2026-09-01
Sources & citations (9)
- Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another thehackernews.com · 2026-09-02
- What happens when AI models take aim at ICS exploits csoonline.com · 2026-09-02
- Frontier AI used to help exploit flaws in tests using key industrial devices ground.news · 2026-09-01
- Security researchers warn of AI-powered PLC attacks in wake of Siemens advisories itpro.com · 2026-09-01
- Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars securityweek.com · 2026-09-01
- Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance gbhackers.com · 2026-09-02
- $536 and 8 Hours: AI Learns to Attack a Different PLC securityaffairs.com · 2026-09-02
- AI is getting closer to being able to exploit OT, and that's very bad news for critical infrastructure tech.yahoo.com · 2026-09-02
- Claude AI Builds Pre-Auth RCE Exploit for WAGO PLC to Execute ARM Shellcode Without Credentials cybersecuritynews.com · 2026-09-02
References
See CVE-2021-31886 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →