Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-67868: S2OPC Server Code Execution through Malicious OPC Requests

CVE-2026-67868 · published 17 days ago
Summary

A vulnerability in S2OPC 1.7.3 allows an attacker to send malicious requests to the server, potentially executing unauthorized code. This could lead to unauthorized access or data corruption. We recommend updating to a patched version of S2OPC to prevent exploitation.

Original advisory text
A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary c...
A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published17 Aug 2026
Updated3 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-67868 · MITRE
Monitor software like this
Free during beta