CVE detail
CVE-2026-63035
A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 7
- within the 30d window
- Peak daily
- 7
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- https://www.o6-automation.com/contactwww.o6-automation.com
No excerpt available.
referencewww.o6-automation.comJul 30, 2026, 11:16 PM - https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97dfgithub.com
No excerpt available.
Exploitgithub.comJul 30, 2026, 11:16 PM - https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804egithub.com
No excerpt available.
Exploitgithub.comJul 30, 2026, 11:16 PM - https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60github.com
No excerpt available.
Exploitgithub.comJul 30, 2026, 11:16 PM - https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179fgithub.com
No excerpt available.
Exploitgithub.comJul 30, 2026, 11:16 PM No excerpt available.
Exploitgithub.comJul 30, 2026, 11:16 PM- o6 Automation open62541CISA Alerts
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code. The following versions of o6 Automation open62541 are affected: open62541 on Windows and Linux >=from_1.3.0| =from_1.4.0| =from_1.5.0| =from_1.3.0| =from_1.4.0| =from_1.5.0| =from_1.3.0| =from_1.4.0| =from_1.5.0| =from_1.3.0| =from_1.4.0| =from_1.5.0| =from_1.3.0| =from_1.4.0| =from_1.5.0|<=1.5.4, o6 Automa
governmentwww.cisa.govJul 30, 2026, 12:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-67300CVSS 8.7 · High
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when Async…
- CVE-2026-67299CVSS 8.7 · High
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update).…
- CVE-2026-10685CVSS 7.6 · High
The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it ha…
- CVE-2026-54522CVSS 2.1 · Low
MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_…
- CVE-2026-13117CVSS 6.0 · Medium
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potent…
- CVE-2026-12996CVSS 6.0 · Medium
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted…