Medium severity6.5NVD Advisory· Published Jul 30, 2026· Updated Sep 3, 2026
CVE-2026-66720
CVE-2026-66720
Description
The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
2- MZ Automation GmbH: Eight Libiec61850 Vulnerabilities Disclosed Together, Causing DoSVypr Intelligence · Jul 30, 2026
- MZ Automation GmbH libiec61850CISA ICS Advisories