What is CVE-2026-63035?
CVE-2026-63035 is a heap use-after-free vulnerability in the TransferSubscriptions service of the open62541 library. It may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code. Users are advised to update the open62541 library to the latest patched version immediately.
Azərbaycanca: CVE-2026-63035, open62541 proqramının TransferSubscriptions xidmətində aşkarlanmış heap use-after-free zəifliyidir. Bu qüsur, autentifikasiya olunmuş təcavüzkara xidmət inkarı (DoS) yaratmağa və ya potensial olaraq sistemdə ixtiyari kod icra etməyə imkan verə bilər. İstifadəçilərə dərhal open62541 kitabxanasını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Which function of the open62541 library is affected by CVE-2026-63035?
This vulnerability was discovered in the TransferSubscriptions service of the open62541 application.
What outcomes can an authenticated attacker achieve by successfully exploiting CVE-2026-63035?
The attacker may cause a denial of service (DoS) or potentially execute arbitrary code on the system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.