Last seen September 2, 2026

Claude Remote Code Execution Vulnerability

Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command

Technical Severity
Low severity
Lifecycle Status

NEW

What Happened

Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command

Why This Matters

The evidence matters to defenders using Claude because it could let an attacker run code in affected environments.

Recommended Action

Confirm whether WAGO is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Sep 02, 2026 13:17

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

AnthropicWAGOClaudeClaude CodeNucleus FTP serverWAGO programmable logic controller (PLC)

Authoritative Intelligence

CVE CVE-2021-31886 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.

Timeline

  • Incident first seen
    Sep 02, 2026 13:17

    BugSkan first recorded this incident.

  • Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
    Sep 02, 2026 13:17

    thehackernews.com · Vulnerability

Sources

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

thehackernews.com · Sep 02, 2026 13:17

Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence