MZ Automation libIEC61850
View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions. The following versions of MZ Automation libIEC61850 are affected: libIEC61850 >=v1.0.0|<=v1.6.1 CVSS Vendor Equipment Vulnerabilities v3 8.1 MZ Automation MZ Automation libIEC61850 Stack-based Buffer Overflow, Heap-based Buffer Overflow, Improper Handling of Syntactically Invalid Structure, NULL Pointer Dereference Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-50039 The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a ReadRequest. View CVE Details Affected Products MZ Automation libIEC61850 Vendor: MZ Automation Product Version: MZ Automation libIEC61850: >=v1.0.0|<=v1.6.1 Product Status: known_affected Remediations Vendor fix MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850. https://github.com/mz-automation/libiec61850 Relevant CWE: CWE-121 Stack-based Buffer Overflow Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-49035 The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled. View CVE Details Affected Products MZ Automation libIEC61850 Vendor: MZ Automation Product Version: MZ Automation libIEC61850: >
CSIRTS triage
- What
- Vulnerabilities could allow unauthenticated attackers to crash services or execute arbitrary code.
- Who is affected
- Users of libIEC61850 versions between v1.0.0 and v1.6.1.
- Urgency
- Remediation is critical due to the potential for remote code execution and denial of service.
- Action
- Update to a version outside the affected range.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch libIEC61850
Get an email when a new libIEC61850 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-500390.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all scored CVEs.
- Low exploitation riskCVE-2026-490350.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-501030.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-500320.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-50039 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-49035 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50103 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50032 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-50103: A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a networ…nvd
- highCVE-2026-50039: The affected product is vulnerable to a stack-based buffer overflow, which may allow an attack…nvd
- highCVE-2026-50032: A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a net…nvd
- highCVE-2026-49035: The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate …nvd
More from CISA Cybersecurity Advisories
- unknownMitsubishi Electric CC-Link IE TSN Communication Protocol2026-07-30
- criticalSchneider Electric IGSS2026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalOpen Source Software: Security Principles and Practices2026-07-30