Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/org.eclipse.milo/milo

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Eclipse Milo versions 0.6.0 through 1.1.4 have a vulnerability where OPC UA server diagnostics nodes do not enforce access authorization. This allows an anonymous client to enable diagnostics without authentication and a trusted client to read sensitive security diagnostics of other sessions, including usernames and authentication details.

Join the discussion

CVE-2026-58080 affects Eclipse Milo versions 1.0.0 through 1.1.4. The vulnerability arises because the OpcUaServerConfig.copy() method does not preserve a configured RoleMapper. This causes sessions to receive no role IDs, leading the default access controller to skip role-permission checks. As a result, anonymous clients can read role-permission metadata, invoke protected methods, or delete protected nodes where anonymous sessions are allowed.

Join the discussion

Eclipse Milo versions 0.6.0 through 1.1.4 contain a vulnerability in the UASC server transport handlers where partial message chunks are not released upon channel disconnection. This allows a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially causing the server to terminate.

Join the discussion

CVE-2026-62927 is a high-severity authorization bypass vulnerability in Eclipse Milo versions 1.0.0 through 1.1.4. The Call service incorrectly dispatches mixed batches of method calls after authorization checks, allowing low-privileged or anonymous clients to execute methods that should be denied by batching them with allowed methods.

Join the discussion

CVE-2026-60007 is a critical vulnerability in Eclipse Milo versions 0.6.0 through 1.1.4 where username-token processing leaks distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures. This flaw allows an on-path attacker to exploit repeated unauthenticated ActivateSession requests as a padding oracle to recover a victim's password and authenticate using the recovered credentials.

Join the discussion

Eclipse Milo versions 1.0.0 through 1.1.4 contain a vulnerability where monitored-item quota accounting is not exception-safe. An unauthenticated remote client can trigger a StackOverflowError by sending deeply nested PubSub ExtensionObjects in a CreateMonitoredItems event filter. This causes the server-global monitored-item quota to be exhausted and prevents new monitored items from being created until the server is restarted. Existing monitored items and other server functions remain unaffected.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:maven/org.eclipse.milo/milo
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses