PatchSiren

Systerel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Systerel CVE published 2026-06-10

CVE-2026-9758

CVE-2026-9758 is a HIGH severity vulnerability with a CVSS score of 7.3. The vulnerability is caused by improper comparison with the certificates trusted list in S2OPC, which allows an attacker to provide a well-formed untrusted certificate to be considered trusted. The vulnerability was published on 2026-06-10T14:16:37.767Z and last modified on 2026-06-10T20:58:26.290Z.

MEDIUM Systerel CVE published 2026-06-09

CVE-2026-6899

CVE-2026-6899 is a MEDIUM severity vulnerability in the CycloneCrypto cryptographic wrapper of the S2OPC library. The issue is that the check for certificate revocation only considers the first matching Certificate Revocation List (CRL) and ignores other valid CRLs of the same Certificate Authority (CA). This could potentially allow a connection between an OPC UA client and server using a revoked certific [truncated]