top of page
perceptive_background_267k.jpg

An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to read
out-of-bounds heap memory, potentia…

Published:

29 July 2026 at 22:00:00

Alert date:

30 July 2026 at 23:02:24

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Network Infrastructure, Zero-Day Vulnerabilities

CVE-2026-63559 describes an integer overflow vulnerability in the UA_Variant arrayDimensions product computation within the open62541 OPC UA library. A remote attacker could exploit this flaw to read out-of-bounds heap memory, potentially disclosing sensitive information. The vulnerability affects the open62541 open-source OPC UA implementation widely used in industrial and OT environments. CISA has issued an ICS advisory (ICSA-26-211-08) regarding this issue. Multiple pull requests and commits have been submitted to the open62541 GitHub repository to address the vulnerability. The flaw is remotely exploitable without authentication, increasing its severity. Affected organizations in critical infrastructure sectors should apply patches promptly.

Technical details

Mitigation steps:

Affected products:

open62541

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page