CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-65423

criticalCVSS 8.8covered by 2 sourcesfirst seen 2026-07-30
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code. The following versions of o6 Automation open62541 are affected: open62541 on Windows and Linux >=from_1.3.0|<=1.3.17 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559) open62541 on Windows and Linux >=from_1.4.0|<=1.4.16 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559) open62541 on Windows and Linux >=from_1.5.0|<=1.5.4 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559) open62541 on Windows and Linux master (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559) CVSS Vendor Equipment Vulnerabilities v3 8.8 o6 Automation GmbH o6 Automation open62541 Integer Underflow (Wrap or Wraparound), Integer Overflow or Wraparound, Use After Free Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-63362 An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet. View CVE Details Affected Products o6 Automation open62541 Vendor: o6 Automation GmbH Product Version: o6 Automation GmbH open62541 on Windows and Linux: >=from_1.3.0|<=1.3.17, o6 Automation GmbH open62541 on Windows and Linux: >=from_1.4.0|<=1.4.16, o6 Automation GmbH open62541 on Windows and Linux: >=from_1.5.0|<=1.5.4, o6 Automation GmbH open62541 on Windows and Linux: master Product Status: known_affected Remediations Mitigation o6 Automation has prepared mitigations and fixes to address these issues and recommends that users update to the newest version. The new version can be obtained by contacting o6 Automation https://www.o6-automation.com/contact or by downloading from the following locations: https://www.o6-

CSIRTS triage

vendor: o6 Automationproduct: open62541Remote code executionDenial of serviceInformation disclosureOtheraffected: >=1.3.0, <=1.3.17; >=1.4.0, <=1.4.16; >=1.5.0, <=1.5.4; master
What
Successful exploitation could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code.
Who is affected
Deployments of open62541 on Windows and Linux in the specified version ranges.
Urgency
Remediation is urgent due to the critical severity and potential for exploitation.
Action
Apply the latest patches for open62541.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-65423

Get an email if CVE-2026-65423 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-65423

CVE.org record

Embed the live status

CVE-2026-65423 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-65423 status](https://www.csirts.com/badge/CVE-2026-65423)](https://www.csirts.com/cve/CVE-2026-65423)