o6 Automation open62541
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code. The following versions of o6 Automation open62541 are affected: open62541 on Windows and Linux >=from_1.3.0|<=1.3.17 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559) open62541 on Windows and Linux >=from_1.4.0|<=1.4.16 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559) open62541 on Windows and Linux >=from_1.5.0|<=1.5.4 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559) open62541 on Windows and Linux master (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559) CVSS Vendor Equipment Vulnerabilities v3 8.8 o6 Automation GmbH o6 Automation open62541 Integer Underflow (Wrap or Wraparound), Integer Overflow or Wraparound, Use After Free Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-63362 An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet. View CVE Details Affected Products o6 Automation open62541 Vendor: o6 Automation GmbH Product Version: o6 Automation GmbH open62541 on Windows and Linux: >=from_1.3.0|<=1.3.17, o6 Automation GmbH open62541 on Windows and Linux: >=from_1.4.0|<=1.4.16, o6 Automation GmbH open62541 on Windows and Linux: >=from_1.5.0|<=1.5.4, o6 Automation GmbH open62541 on Windows and Linux: master Product Status: known_affected Remediations Mitigation o6 Automation has prepared mitigations and fixes to address these issues and recommends that users update to the newest version. The new version can be obtained by contacting o6 Automation https://www.o6-automation.com/contact or by downloading from the following locations: https://www.o6-
CSIRTS triage
- What
- Successful exploitation could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code.
- Who is affected
- Deployments of open62541 on Windows and Linux in the specified version ranges.
- Urgency
- Remediation is urgent due to the critical severity and potential for exploitation.
- Action
- Apply the latest patches for open62541.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch open62541
Get an email when a new open62541 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-633621.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 72% of all scored CVEs.
- Low exploitation riskCVE-2026-654230.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all scored CVEs.
- Low exploitation riskCVE-2026-630350.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all scored CVEs.
- Low exploitation riskCVE-2026-635590.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-63362 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65423 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63035 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63559 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-65423: An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may all…nvd
- mediumCVE-2026-63362: An unsigned integer underflow in the PubSub signature verification path in open62541 may allow…nvd
- highCVE-2026-63035: A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allo…nvd
- highCVE-2026-63559: An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may all…nvd
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalMZ Automation GmbH libiec618502026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30