CVE-2026-37534Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Transport_Protocol_Data_Transfer,allows attackers to write to arbitrary memory via crafted sequence number from the CAN frame.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-191

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-12)
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
01234Mentions · 2026-05-01: 3Mentions · 2026-05-12: 4Technical Details · 2026-05-01: 3Technical Details · 2026-05-12: 305-0105-12
Signal classification2 categories
Disclosure
457.1%
General
342.9%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-013
Disclosure3
2026-05-124
Disclosure1General3
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    General

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-37534 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory announces a critical CVE-2026-37534 with a high CVSS score but provides no proof‑of‑concept, exploit, active exploitation, or patch details.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-37534 (CVSS 9.8) — multiple products. CVE: CVE-2026-37534 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces a critical CVE-2026-37534 with a CVSS 9.8 score and advisory status, but provides no PoC, exploit, or patch details.

    1000030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-37534 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in…

    Post summary

    An integer underflow vulnerability (CVE-2026-37534) in Open-SAE-J1939 with CRITICAL severity is noted, but the post lacks exploit code, PoC, patch information, or reports of active exploitation.

    1000028
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-37534 Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Transport_Protocol_Data_Transfer… https://www.cve.org/CVERecord?id=CVE-2026-37534

    Post summary

    The provided text announces a newly disclosed integer underflow vulnerability in Open‑SAE‑J1939, identified by commit b6caf884, with a CVE record link for additional details.

    00010150
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-37534-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text only links to a CVE advisory with no additional details or claims.

    0000020
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-37534 Integer Underflow in Open-SAE-J1939 Allows Arbitrary Memo... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-37534 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE-2026-37534, citing an integer underflow in Open‑SAE‑J1939, and directs readers to a vulnerability details page, but does not provide PoC, exploit code, patch, or evidence of active exploitation.

    0000041
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-37534 Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Transport_Protocol_Data_Transfer… https://www.cve.org/CVERecord?id=CVE-2026-37534 ----- Traducción: CVE-2026-37534 vul… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-37534 as an integer underflow vulnerability in Open‑SAE‑J1939, citing a specific commit, without providing proof of exploitation or remediation details.

    0000026
    75 followersView on X

Explore more