CVE-2026-67868

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.

Published 2026-08-17. Last modified 2026-09-09.