s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-67857

📛 CVE Title

CVE-2026-67857

Description

open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.

Overview

State
PUBLISHED
Assigner (CNA)
mitre
CVSS severity
HIGH
CVSS score
CVSS 7.5 / 10 7.5 7.5 / 10
CVSS vector
CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N
Effective score
7.5 / 10 HIGH source: CNA overview
CWE(s)
Reserved
2026-07-30
Published
2026-08-04 00:00 UTC
Last updated
2026-08-05 14:31 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/67xxx/CVE-2026-67857.json
Linked Threat
CVE-2026-67857 — CVE-2026-67857

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-08-04 22:17:15 UTC
NVD last modified
2026-08-05 15:17:06 UTC
NVD CVSS v3.1
CVSS 7.5 / 10 7.5 7.5 / 10 HIGH source: cve@mitre.org
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability subscore
3.9 / 10
Impact subscore
3.6 / 10
EPSS score
0.0035 (probability of exploitation in next 30 days)
EPSS percentile
27.67% vs all CVEs — higher = more likely to be exploited, as of 2026-08-05

NVD-assigned CWE(s): CWE-125 (differs from the CNA list above)

NVD / KEV / EPSS data refreshed 2026-08-06 02:35 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-52967
Assigner
mitre
Published
Aug 4, 2026, 12:00:00 AM
Updated
Aug 5, 2026, 2:31:49 PM
EUVD base score (CVSS 3.1)
7.5 / 10
CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N
EUVD-reported EPSS
0.0000
Vendors
n/a
Products
n/a (n/a)
Aliases
GHSA-2mh5-cmr8-pwvp

ENISA description: open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.

EUVD references (5)

Affected products (1)

VendorProductVersionsPlatforms
n/a n/a n/a (affected)

Vendor references (5)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

NVD-tagged references (6)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (10)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:access.redhat.com

    A flaw was found in open62541. A remote attacker could exploit an out-of-bounds read vulnerability in the client-side function responseReadNamespacesArray () by sending a specially crafted network packet. This could lead to a denial of service, causing the application to crash and become unavailable.

    2026-08-06 01:15 UTC
  • web:compliancehub.wiki

    CVE - 2026 -18577 bypasses the N-able N-central patch , giving admin access and endpoint pivot via Take Control. KEV deadline 6 August 2026 — response and IOCs.

    2026-08-06 01:15 UTC
  • web:cybersecuritynews.com

    Apple has released iOS 26.6 and iPadOS 26.6 to fix security flaws that could enable kernel code execution, root access, and sandbox escape.

    2026-08-06 01:15 UTC
  • web:nvd.nist.gov

    CVE - 2026 -18577 Detail Description An incomplete patch for CVE - 2026 -18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

    2026-08-06 01:15 UTC
  • web:status.n-able.com

    If you identify any of these, contact N-able support immediately and engage your own security team. Supported Upgrade Paths Upgrade directly to 2026.3.1 from 2025.4 2026.1 2026.2 2026.3 If you are on an older version, we recommend going to any of the builds above. Then upgrade to this Hotfix version ASAP. If you are unsure of what to do, you can contact support directly. Do I need to update my ...

    2026-08-06 01:15 UTC
  • web:techcommunity.microsoft.com

    We wanted to tell you how to address the Exchange Server May 2026 vulnerability CVE - 2026 -42897.

    2026-08-06 01:15 UTC
  • web:vulners.com

    CVE-2026-67857 🗓️ 03 Aug 2026 17:00:00 Reported by mitre Type cve 🔗 web.nvd.nist.gov 👁 11 Views

    2026-08-06 01:15 UTC
  • web:www.n-able.com

    As our investigation progressed, we determined the vulnerability affected all versions of N‑central and released a comprehensive hotfix (2026.3.1.7) on August 2: N‑central 2026.3 Hotfix 1 - Mitigation for CVE - 2026 -18577.

    2026-08-06 01:15 UTC
  • web:www.oracle.com

    Additional CVEs addressed are: The patch for CVE - 2026 -34481 also addresses CVE - 2026 -34477, CVE - 2026 -34478, CVE - 2026 -34479, and CVE - 2026 -34480. Oracle Fusion Middleware Risk Matrix This Critical Security Patch Update contains 106 new security patches for Oracle Fusion Middleware. 53 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a ...

    2026-08-06 01:15 UTC
  • web:www.theregister.com

    CVE - 2026 -18577 is related to an earlier flaw, CVE - 2026 -18556, patched in N-central 2026.2. According to N-able, that fix left another route to exploitation, which attackers began abusing late last month. CISA gave Federal Civilian Executive Branch agencies until August 6 to remediate the flaw. Under Binding Operational Directive 26-04, CISA can impose a three-day deadline on vulnerabilities it ...

    2026-08-06 01:15 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-67857.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-67857",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-05T14:31:17.935192Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-125",
                "description": "CWE-125 Out-of-bounds Read",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-05T14:31:49.820Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/open62541/open62541/issues/8104"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "n/a",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "n/a",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-04T21:21:25.605Z",
        "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "shortName": "mitre"
      },
      "references": [
        {
          "url": "https://github.com/open62541/open62541/issues/8104"
        },
        {
          "url": "https://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_connect.c"
        },
        {
          "url": "https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect.c"
        },
        {
          "url": "https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect_loop.c"
        },
        {
          "url": "https://github.com/gff-cw/information/issues/9"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
    "assignerShortName": "mitre",
    "cveId": "CVE-2026-67857",
    "datePublished": "2026-08-04T00:00:00.000Z",
    "dateReserved": "2026-07-30T00:00:00.000Z",
    "dateUpdated": "2026-08-05T14:31:49.820Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}