PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-71643 ZJU-FAST-Lab CVE debrief

CVE-2026-71643 is a high-severity vulnerability in the EGO-Planner-v2 component, specifically affecting the EGOReplanFSM component, which could allow an attacker to cause a denial of service. The CVE record was published on 2026-09-10T22:16:58.940Z and was last modified on 2026-09-14T18:19:48.243Z. The NVD entry is currently has not been modified since then.

Vendor
ZJU-FAST-Lab
Product
EGO-Planner-v2
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-10
Original CVE updated
2026-09-14
Advisory published
2026-09-10
Advisory updated
2026-09-14

Who should care

Defenders and system administrators using EGO-Planner-v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42 should assess exposure and verify the version in use. Defenders should prioritize verifying the affected versions and assessing exposure in their systems, especially those using EGO-Planner-v2. The vulnerability could allow an attacker to cause a denial of service, and defenders should review system configurations and ensure EGOReplanFSM component

Why it matters

CVE-2026-71643 is a high-severity vulnerability in EGO-Planner-v2 that could allow an attacker to cause a denial of service. Defenders should prioritize verifying the affected versions and assessing exposure in their systems.

  • Potential denial of service attacks against systems using EGO-Planner-v2
  • Need to verify affected versions and assess exposure in systems

Technical summary

The EGO-Planner-v2 component, specifically the EGOReplanFSM component, is vulnerable to a denial of service attack. The CVE record and NVD detail page provide information on the vulnerability, but the specific versions affected and the exact impact require further verification from the official sources. Defenders should prioritize verifying the affected versions and assessing exposure in their systems, especially those using EGO-Planner-v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42. The vulnerability could allow an attacker to cause a denial of service, and defenders should review

Defensive priority

Defenders should prioritize verifying the affected versions and assessing exposure in their systems, especially those using EGO-Planner-v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42.

Recommended defensive actions

  • Verify the version of EGO-Planner-v2 in use and assess exposure
  • Review system configurations and ensure EGOReplanFSM component is properly secured
  • Monitor system logs for potential denial of service attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, but the specific versions affected and the exact impact require further verification from the official sources. Defenders should verify the affected versions and assess exposure in their systems, especially those using EGO-Planner-v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42. The EGOReplanFSM component is vulnerable to a denial of service attack, and defenders should prioritize verifying the affected versions and assessing exposure in their

Sources and references

Verified primary and authoritative sources

  • CVE-2026-71643 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-71643

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-71643 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71643

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.