# o6 Automation open62541 OPC UA Flaws Patched

Published: 2026-07-30 · Severity: medium · Sectors: energy, transportation
Canonical: https://vorant.io/reports/c3304a67-3cb9-54d6-ad3f-63b8eaf2d125/o6-automation-open62541-opc-ua-flaws-patched

> CISA warns of four vulnerabilities in o6 Automation's open62541 OPC UA stack that could enable DoS, information disclosure, or remote code execution.

CISA published an ICS advisory detailing four vulnerabilities in open62541, an open-source OPC UA implementation used by o6 Automation GmbH (Germany) across Windows and Linux deployments in critical manufacturing, energy, and transportation sectors worldwide. The flaws span multiple versions from 1.3.0 through 1.5.4 and the master branch, and include an integer underflow in PubSub signature verification (CVE-2026-63362) that can cause denial of service via crafted UDP packets, two integer overflow issues in UA_Variant arrayDimensions computation (CVE-2026-65423 and CVE-2026-63559) leading to out-of-bounds write and out-of-bounds heap read respectively, and a heap use-after-free in the TransferSubscriptions service (CVE-2026-63035) that could allow an authenticated attacker to cause DoS or potentially execute arbitrary code.

The vendor has prepared fixes referenced in open62541 GitHub pull requests and security advisories SA-2026-0012, SA-2026-0014, and SA-2026-0015, and recommends organizations update to the latest version or contact o6 Automation directly. CISA notes no known public exploitation targeting these vulnerabilities at this time, and recommends standard ICS defensive measures including network isolation, firewalling control system networks, and secure remote access via VPN. The vulnerabilities were reported to CISA by researchers Asher Davila (Palo Alto Networks) and Abhinav Agarwal.

## Mentioned in this report

- Vulnerabilities: CVE-2026-63035, CVE-2026-63362, CVE-2026-63559, CVE-2026-65423

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c3304a67-3cb9-54d6-ad3f-63b8eaf2d125/o6-automation-open62541-opc-ua-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
