{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3as2opcs2opc/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:s2opc:s2opc:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.3,"id":"CVE-2026-90782"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["S2OPC (\u003c= 1.7.3)"],"_cs_severities":["medium"],"_cs_tags":["industrial-control-systems","denial-of-service","vulnerability"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-90782 is a memory-related vulnerability in S2OPC (Safe \u0026amp; Secure OPC) versions 1.7.3 and earlier. The flaw resides within the \u003ccode\u003ealloc_notification_message_items()\u003c/code\u003e function, where a single shared status variable is reused for both DataChange and Event memory allocations. An error in the allocation logic allows the status variable to be incorrectly overwritten to \u003ccode\u003eSOPC_STATUS_OK\u003c/code\u003e if a DataChange allocation fails but a subsequent Event allocation succeeds. This logic failure causes the application to bypass safety checks and proceed to dereference a NULL pointer (\u003ccode\u003edataChangeNotif\u003c/code\u003e), resulting in a crash and denial-of-service condition for the affected service. A public proof-of-concept (PoC) exploit has been released, demonstrating the crash by manipulating the allocation failure path.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in an application-level denial-of-service (DoS) condition. As the target is an OPC UA stack, successful exploitation can lead to loss of availability for critical industrial communication services, potentially disrupting process monitoring or control functions in environments where S2OPC is deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of S2OPC instances.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all deployments of S2OPC to the version containing the fix for CVE-2026-90782 (referencing the logic pattern in commit 8848f051).\u003c/li\u003e\n\u003cli\u003eReview industrial network monitoring logs for service instability or recurring crashes associated with OPC UA services.\u003c/li\u003e\n\u003cli\u003eImplement memory safety monitoring tools like AddressSanitizer (ASan) in development and staging environments to proactively detect memory corruption or NULL dereference vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T06:12:06Z","date_published":"2026-09-14T06:12:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-s2opc-cve-2026-90782/","summary":"CVE-2026-90782 is a NULL pointer dereference vulnerability in S2OPC 1.7.3 and earlier, allowing an attacker to trigger a denial-of-service crash via manipulated allocation sequences.","title":"NULL Pointer Dereference Vulnerability in S2OPC","url":"https://feed.craftedsignal.io/briefs/2026-09-s2opc-cve-2026-90782/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:s2opc:s2opc:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}