← Back to Feed
MZ Automation GmbH libiec61850
CVE-2026-66720CVE-2026-66369CVE-2026-63550CVE-2026-65421CVE-2026-66364CVE-2026-66349CVE-2026-56758CVE-2026-66360
July 30, 2026 · CISA (US-CERT) · Severity: CRITICAL
MZ Automation libiec61850 contains multiple out-of-bounds read vulnerabilities affecting the GOOSE subscriber component. An unauthenticated attacker can send specially crafted multicast frames to trigger a heap out-of-bounds read, leading to a denial-of-service condition. The vendor advises updating to version 1.6.2.
Key Takeaways
- Multiple out-of-bounds read vulnerabilities in MZ Automation libiec61850.
- Crafted GOOSE frames can cause heap out-of-bounds read and crash.
- Update to version 1.6.2 to mitigate denial-of-service risks.