CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

MZ Automation GmbH libiec61850

criticalCVE-2026-66720CVE-2026-66369CVE-2026-63550CVE-2026-65421CVE-2026-66364CVE-2026-66349
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec61850 are affected: libiec61850 <1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360) CVSS Vendor Equipment Vulnerabilities v3 7.5 MZ Automation GmbH MZ Automation GmbH libiec61850 Out-of-bounds Read Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-66720 The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH libiec61850: <1.6.2 Product Status: known_affected Remediations Mitigation MZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-66369 The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service. View CVE Details Affected Products

CSIRTS triage

What
Vulnerabilities could cause a denial-of-service condition on the device.
Who is affected
Users of MZ Automation GmbH libiec61850 versions prior to 1.6.2.
Urgency
Remediation is critical due to the potential for denial-of-service attacks.
Action
Update libiec61850 to version 1.6.2 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch libiec61850

Get an email when a new libiec61850 advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-07-30
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-66720coverage & exploitation statusNVD · CVE.org
CVE-2026-66369coverage & exploitation statusNVD · CVE.org
CVE-2026-63550coverage & exploitation statusNVD · CVE.org
CVE-2026-65421coverage & exploitation statusNVD · CVE.org
CVE-2026-66364coverage & exploitation statusNVD · CVE.org
CVE-2026-66349coverage & exploitation statusNVD · CVE.org
CVE-2026-56758coverage & exploitation statusNVD · CVE.org
CVE-2026-66360coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories