CVE-2026-37539

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFrame allowing remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted CAN FD frames.

Published 2026-05-01. Last modified 2026-06-17.