IM
IronMonkey Threat Research
‹ Back to ICS Advisories

o6 Automation open62541

HIGH
CVSS 8.8
Date 2026-07-30T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code.

// Vulnerabilities (4)

CVE ID CVSS Score Severity Description
CVE-2026-65423 8.8 high
An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.
CVE-2026-63035 8.1 high
A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.
CVE-2026-63559 7.5 high
An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.
CVE-2026-63362 5.9 medium
An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.

// Remediations (6)

Mitigation: https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df
https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df
Mitigation: https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e
https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e
Mitigation: https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f
https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f
Mitigation: https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60
https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60
Mitigation: For more information, see open62541 Security Advisories SA-2026-0012, SA-2026-0014, and SA-2026-0015
For more information, see open62541 Security Advisories SA-2026-0012, SA-2026-0014, and SA-2026-0015 or contact o6 Automation: https://www.o6-automation.com/contact
Mitigation: o6 Automation has prepared mitigations and fixes to address these issues and recommends that users u
o6 Automation has prepared mitigations and fixes to address these issues and recommends that users update to the newest version. The new version can be obtained by contacting o6 Automation https://www.o6-automation.com/contact or by downloading from the following locations:

// References