What you need to know today.
Industrial control systems from MZ Automation, Open62541, and others are affected by numerous high-severity vulnerabilities, including RCE and DoS risks.
A significant number of vulnerabilities have been disclosed across various industrial control systems and communication protocols. MZ Automation products are particularly affected, with multiple advisories detailing flaws in their libiec61850, lib60870, and other components. These vulnerabilities, including buffer overflows, use-after-free errors, and improper handling of data lengths, could lead to denial of service, arbitrary code execution, or sensitive information disclosure. Specific CVEs include CVE-2026-56758, CVE-2026-63550, CVE-2026-65421, CVE-2026-66349, CVE-2026-66360, CVE-2026-66364, CVE-2026-66369, CVE-2026-66720, CVE-2026-61893, and CVE-2026-63033. These advisories highlight the critical need for patching and secure configuration in these environments, as detailed in CISA ICS Advisories.
Open62541, an open-source implementation of OPC UA, has several vulnerabilities disclosed, including integer overflows and heap-based vulnerabilities. CVE-2026-65423 and CVE-2026-63559 describe integer overflows in the UA_Variant arrayDimensions product computation, potentially leading to out-of-bounds writes or reads of heap memory, which could disclose sensitive information. CVE-2026-63035 details a use-after-free vulnerability in the TransferSubscriptions service, which could allow for denial of service or arbitrary code execution. Additionally, CVE-2026-63362 points to an unsigned integer underflow in PubSub signature verification, enabling denial of service via crafted UDP packets. These issues are detailed in CISA ICS Advisory icsa-26-211-08.
Several other industrial and communication systems are impacted by newly disclosed vulnerabilities. Toptech Systems' RCU II+ and Multiload II+ devices are vulnerable to an unauthenticated debug interface that grants root-level access (CVE-2026-12562), as noted by CISA. Mitsubishi Electric's CC-Link IE TSN communication protocol has a vulnerability related to improper enforcement of message integrity, potentially allowing network-based attackers to compromise the system (CVE-2026-13584). NASA's Core Flight System (cFS) Health and Safety (HS) application has a NULL pointer dereference vulnerability due to an incomplete fix for a previous issue (CVE-2026-18064). Rockwell Automation's CompactLogix and ControlLogix controllers have a CIP Security certificate revocation handling flaw (CVE-2026-9636). Lastly, IGSS is affected by an out-of-bounds write vulnerability when importing malicious CGF files, posing risks of data loss or code execution (CVE-2026-12927).