CISA Advises on Multiple Critical Vulnerabilities in o6 Automation open62541
CISA has issued an advisory detailing four critical vulnerabilities in o6 Automation's open62541 library, potentially allowing remote attackers to execute arbitrary code, cause denial-of-service, or disclose sensitive information.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a critical advisory concerning multiple vulnerabilities discovered in o6 Automation's open62541 software, a component widely deployed across various critical infrastructure sectors globally. The identified flaws, including CVE-2026-63362 (Integer Underflow), CVE-2026-65423 (Integer Overflow), CVE-2026-63035 (Use After Free), and CVE-2026-63559, affect several versions of the open62541 library on both Windows and Linux operating systems, including the master branch.
Successful exploitation of these vulnerabilities could grant an attacker significant control over affected systems. Specifically, CVE-2026-63362, an unsigned integer underflow in the PubSub signature verification path, could enable a remote attacker to cause a denial-of-service (DoS) by sending a crafted UDP packet. This vulnerability has a CVSS v3.1 score of 5.9 (MEDIUM) and a CVSS v4.0 score of 8.8 (HIGH).
Another critical flaw, CVE-2026-65423, involves an integer overflow in the UA_Variant arrayDimensions product computation. This could allow a remote attacker to trigger an out-of-bounds write, potentially leading to information disclosure, denial of service, or arbitrary code execution. This vulnerability carries a higher CVSS v3.1 score of 8.8 (HIGH) and a CVSS v4.0 score of 8.7 (HIGH).
The advisory also highlights CVE-2026-63035, a heap use-after-free vulnerability within the TransferSubscriptions service. An authenticated attacker could exploit this flaw to cause a denial-of-service or potentially execute arbitrary code on the affected system. The CVSS scores for this vulnerability are 8.8 (HIGH) for v3.1 and 8.2 (HIGH) for v4.0.
While CVE-2026-63559 is listed, specific details regarding its technical mechanism and impact are not fully elaborated in the initial advisory, though it is grouped with the other vulnerabilities that can lead to information disclosure, DoS, or arbitrary code execution.
The affected versions of open62541 include those from 1.3.0 up to 1.3.17, 1.4.0 up to 1.4.16, and 1.5.0 up to 1.5.4, as well as the master branch. These versions are utilized in critical infrastructure sectors such as Critical Manufacturing, Energy, and Transportation Systems, with deployments reported worldwide.
o6 Automation GmbH has acknowledged these vulnerabilities and has released mitigations and fixes. The company strongly recommends that users update to the latest available version of the open62541 library. Information on obtaining the updated versions and specific mitigation steps can be found by contacting o6 Automation directly or by referencing the provided GitHub pull requests and security advisories (SA-2026-0012, SA-2026-0014, and SA-2026-0015).
CISA urges asset owners to review the advisory and apply the necessary updates and mitigations promptly to protect their operational technology environments from potential exploitation. The widespread use of this library in industrial control systems underscores the importance of addressing these vulnerabilities to maintain the integrity and availability of critical infrastructure.