VYPR
AI Brief2026-07-31· generated Jul 31, 2026

ICS Vulnerabilities Plague Multiple Industrial Systems

Industrial control systems are hit by multiple vulnerabilities in MZ Automation, Open62541, Toptech Systems, and NASA software, with some allowing root access or code execution.

MZ Automation GmbH's libiec61850 library is affected by eight vulnerabilities, including several buffer overflows and out-of-bounds reads and writes. These flaws, detailed in CISA ICS Advisory ICSA-26-211-10, could allow unauthenticated attackers to cause denial-of-service conditions or potentially execute arbitrary code. The vulnerabilities stem from improper handling of various data fields within protocols like MMS and GOOSE, including issues with length checks and boundary handling during data parsing. Exploitation could impact industrial control systems relying on these protocols for communication and control. CVEs involved include CVE-2026-56758, CVE-2026-63550, CVE-2026-65421, CVE-2026-66349, CVE-2026-66360, CVE-2026-66364, CVE-2026-66369, and CVE-2026-66720.

Open62541, an open-source implementation of the OPC UA protocol, has four vulnerabilities disclosed, with three rated high severity. CVE-2026-65423 and CVE-2026-63559 are integer overflows in the UA_Variant arrayDimensions computation, potentially leading to out-of-bounds writes or heap memory reads, which could disclose sensitive information. CVE-2026-63035, a heap use-after-free in the TransferSubscriptions service, could allow authenticated attackers to achieve denial-of-service or arbitrary code execution. These vulnerabilities, highlighted by CISA ICS Advisory ICSA-26-211-08, pose a risk to systems using OPC UA for industrial communication.

Toptech Systems' RCU II+ and Multiload II+ devices are vulnerable to an unauthenticated debug interface that grants root-level access. This critical flaw, detailed in CISA ICS Advisory ICSA-26-211-03, stems from a network-accessible port running a debug service that lacks proper authentication. An attacker could exploit this to gain complete control over the embedded system, potentially disrupting operations or exfiltrating sensitive data.

NASA's core Flight System (cFS) Health and Safety (HS) application has a NULL pointer dereference vulnerability due to an incomplete fix for a previous issue. This flaw, CVE-2026-18064, exists in versions up to 7.0.1 and can be triggered by an attacker who can send a specific command. Successful exploitation could lead to a denial-of-service condition, impacting critical flight operations. CISA ICS Advisory ICSA-26-211-06 provides further details.

Mitsubishi Electric's CC-Link IE TSN communication protocol suffers from a vulnerability related to improper enforcement of message integrity. This flaw, CVE-2026-13584, could allow an attacker with network access to manipulate communication, potentially leading to unauthorized control or data manipulation within industrial networks. CISA ICS Advisory ICSA-26-211-07 outlines the risks associated with this vulnerability.

IGSS, an industrial SCADA system, has an out-of-bounds write vulnerability in its handling of CGF files. CVE-2026-12927 could allow an attacker to cause data loss or potentially execute arbitrary code by importing a malicious CGF file into IGSS Definition. This vulnerability was reported by The Hacker News and detailed in CISA ICS Advisory ICSA-26-211-04.

Project Koku's koku-metrics-operator is affected by multiple vulnerabilities allowing for token exfiltration. CVE-2026-18378 and CVE-2026-18381 involve cluster pull-secret and service-account token exfiltration, respectively, via user-controlled URLs. CVE-2026-18382 allows service-account client credentials to be sent to a user-controlled token URL. These SSRF and confused deputy vulnerabilities could lead to unauthorized access and privilege escalation.

MZ Automation GmbH's lib60870 library contains two vulnerabilities, CVE-2026-61893 and CVE-2026-63033, related to the IEC 60870-5-104 protocol. These flaws involve reading past the end of a heap-allocated message buffer due to crafted I-frames with inflated object counts or declared object counts exceeding the ASDU body. Exploitation could lead to denial-of-service conditions. CISA ICS Advisory ICSA-26-211-11 provides details on these vulnerabilities.

Synthesized by Vypr AI
ICS Vulnerabilities Plague Multiple Industrial Systems · VYPR