Critical Integer Underflow/Overflow Flaws in o6 Automation open62541 Library (CVE‑2026‑63362‑63559) Threaten Industrial Control Systems
What It Is — CISA has identified four high‑severity vulnerabilities (CVE‑2026‑63362, CVE‑2026‑65423, CVE‑2026‑63035, CVE‑2026‑63559) in the open62541 OPC UA stack used on Windows and Linux. The flaws include integer underflow/overflow and a use‑after‑free that can be triggered by crafted UDP packets.
Exploitability — CVSS v3 score 8.8 (High). Public proof‑of‑concepts have been released, and active exploitation could lead to remote code execution or denial‑of‑service.
Affected Products — o6 Automation open62541 library versions 1.3.0‑1.3.17, 1.4.0‑1.4.16, 1.5.0‑1.5.4, and the current master branch on both Windows and Linux.
Why It Matters for Compliance & Audit Readiness
- Mapping these flaws to SOC 2 Control CC6.1 (System Operations) demonstrates due‑diligence in managing software supply‑chain risk.
- Continuous evidence collection of patch status feeds audit trails that prove you remediate critical control gaps promptly.
- A documented control‑mapping process satisfies the “Change Management” and “Vulnerability Management” criteria that enterprise buyers now demand in SOC 2 reports.
Recommended Actions
- Inventory every system that embeds open62541 and verify the exact version deployed.
- Apply the vendor‑provided patches or upgrade to a non‑vulnerable release immediately.
- Map the vulnerability to your SOC 2 control matrix (e.g., CC6.1, CC7.2) and capture patch‑status evidence in your continuous‑compliance platform.
- Enable network‑level filtering for unexpected UDP traffic to mitigate exploitation while patches are applied.
Source: CISA Advisory – ICSA‑26‑211‑08