Two high-severity vulnerabilities in the open-source BACnet Stack C library allow unauthenticated remote attackers to trigger out-of-bounds reads in BACnet/IP property decoding logic on embedded devices. CVE-2026-41503 affects the ReadPropertyMultiple service, where rpm_decode_object_property() uses the deprecated decode_tag_number_and_value() parser without a buffer length, enabling a crafted truncated property list with a 1-byte payload and extended tag marker 0xF9 to read 1 byte past the end of the buffer. CVE-2026-41475 affects the WritePropertyMultiple service, where wpm_decode_object_property() invokes the same deprecated parser without proper bounds checking, allowing a truncated request to read 1 to 7 bytes out of bounds.
The flaws affect BACnet Stack versions prior to 1.4.3 and are classified as CWE-125. Reported impact includes denial of service through crashes on embedded BACnet devices, with the WritePropertyMultiple issue also carrying potential information disclosure risk. The vulnerable code paths are reachable over the network with no authentication or user interaction, and the ReadPropertyMultiple confirmed service handler is enabled by default in the reference server. Both issues were addressed in version 1.4.3, with a GitHub security advisory published alongside the disclosures.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A GitHub security advisory was published for CVE-2026-41475, documenting the out-of-bounds read in the WritePropertyMultiple decoder and its remediation in BACnet Stack 1.4.3.
A new CVE, CVE-2026-41502, was published for an off-by-one out-of-bounds read in BACnet Stack's ReadPropertyMultiple object ID decoder. The flaw affects versions prior to 1.4.3, can be triggered remotely with a crafted truncated request, and was remediated in version 1.4.3.
Two CVEs were published for BACnet Stack: CVE-2026-41475 in the WritePropertyMultiple decoder and CVE-2026-41503 in the ReadPropertyMultiple decoder. Both issues stem from use of the deprecated decode_tag_number_and_value() parser without proper buffer-length handling and primarily impact embedded BACnet devices.
BACnet Stack version 1.4.3 fixed two out-of-bounds read flaws in the ReadPropertyMultiple and WritePropertyMultiple service decoders. The bugs affected versions prior to 1.4.3 and could be triggered remotely with crafted truncated BACnet/IP requests, causing crashes and possible limited information disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.