SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66369

MEDIUM · CVSS 6.5 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The vulnerability exists in the GOOSE parser, which is susceptible to an off-by-one boundary-handling flaw triggered by unauthenticated Layer-2 multicast frames. This flaw leads to a heap out-of-bounds read, resulting in the termination of the subscriber process and causing a denial-of-service condition. Organizations utilizing affected platforms should prioritize patching this vulnerability to mitigate potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66369
Severity
MEDIUM
CVSS
6.5
EPSS
0.18%

Original NVD Description

The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service.