Military & Security

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

· September 2, 2026
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

What happened

Forescout Research’s Vedere Labs used Anthropic’s Claude AI to successfully port a remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) model to another. The exploit targets CVE-2021-31886, a stack-based buffer overflow vulnerability in the Nucleus FTP server’s handling of the USER command. This allowed the researchers to execute attacker-supplied ARM shellcode on live hardware without needing prior authentication.

The risk

PLC systems run critical infrastructure and industrial processes. This exploit shows attackers can leverage AI tools to adapt complex exploits quickly across device variants. Pre-authentication RCE vulnerabilities give attackers direct control over industrial hardware, raising the risk of disruptive or destructive actions without requiring initial access or credentials. The underlying flaw remains unpatched on many devices.

Why it matters

Using Claude to automate exploit porting lowers the technical barrier for attackers and increases the speed of weaponizing industrial vulnerabilities across multiple device models. This pressures industrial operators and security teams to improve patch management, network segmentation, and threat detection around PLC systems. It also highlights how AI is changing offensive security by enabling rapid exploit adaptation and testing on real hardware.

Who should pay attention

Industrial operators, OT security teams, and vulnerability researchers must monitor this development. AI-assisted exploit porting raises the stakes in industrial cybersecurity, requiring more proactive defenses for embedded and critical infrastructure devices. Security vendors working on PLC protection should consider AI-powered attack techniques when designing detection and mitigation strategies.

What to watch next

Watch for follow-up research demonstrating AI tools porting additional PLC exploits and cross-platform weaponization. Regulators and industrial standards bodies could respond with stricter vulnerability disclosure and patching requirements. Security vendors may accelerate development of AI-powered defensive tools aimed at detecting AI-assisted exploitation in OT environments. Finally, broader adoption of AI in offensive security could reshape risk profiles for industrial networks.

AI Quick Briefs Editorial Desk

Stay ahead of AI Get the most important AI news delivered to your inbox — free.