CVE-2026-66360
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec61850 are affected: libiec61850 <1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360) CVSS Vendor Equipment Vulnerabilities v3 7.5 MZ Automation GmbH MZ Automation GmbH libiec61850 Out-of-bounds Read Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-66720 The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH libiec61850: <1.6.2 Product Status: known_affected Remediations Mitigation MZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-66369 The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service. View CVE Details Affected Products
CSIRTS triage
- What
- Vulnerabilities could cause a denial-of-service condition on the device.
- Who is affected
- Users of MZ Automation GmbH libiec61850 versions prior to 1.6.2.
- Urgency
- Remediation is critical due to the potential for denial-of-service attacks.
- Action
- Update libiec61850 to version 1.6.2 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-66360
Get an email if CVE-2026-66360 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
Advisory coverage (2)
- highCVE-2026-66360: The ISO Presentation layer contains a flaw in the handling of specific parameters during norma…nvd · 2026-07-30
- criticalMZ Automation GmbH libiec61850cisa · 2026-07-30
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-66360)