


Perceptive Security
SOC/SIEM Consultancy

An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to read
out-of-bounds heap memory, potentia…
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 23:02:24
Source:
nvd.nist.gov
Critical Infrastructure, Network Infrastructure, Zero-Day Vulnerabilities
CVE-2026-63559 describes an integer overflow vulnerability in the UA_Variant arrayDimensions product computation within the open62541 OPC UA library. A remote attacker could exploit this flaw to read out-of-bounds heap memory, potentially disclosing sensitive information. The vulnerability affects the open62541 open-source OPC UA implementation widely used in industrial and OT environments. CISA has issued an ICS advisory (ICSA-26-211-08) regarding this issue. Multiple pull requests and commits have been submitted to the open62541 GitHub repository to address the vulnerability. The flaw is remotely exploitable without authentication, increasing its severity. Affected organizations in critical infrastructure sectors should apply patches promptly.
Technical details
Mitigation steps:
Affected products:
open62541
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-63559
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-08.json
https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f
https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60
https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e
https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df
https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08
https://www.o6-automation.com/contact
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
