VYPR
advisoryPublished Jul 23, 2026· 2 sources

CISA Warns of Denial-of-Service Vulnerability in MZ Automation lib60870

A critical out-of-bounds read vulnerability in MZ Automation's lib60870 library could allow attackers to crash industrial control systems, impacting sectors like energy and water.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a new advisory detailing a critical vulnerability within MZ Automation's lib60870 software library. Identified as CVE-2026-16002, the flaw is an out-of-bounds read that could lead to a denial-of-service (DoS) condition by crashing the parsing process.

This vulnerability affects all versions of lib60870 up to and including version 2.4.0. The lib60870 library is a crucial component used in industrial control systems (ICS) and operational technology (OT) environments, particularly those dealing with the IEC 60870 standard for telecontrol, which is prevalent in sectors such as chemical, energy, and water and wastewater management.

Successful exploitation of CVE-2026-16002 would allow an unauthenticated attacker to remotely trigger the crash. The CVSS v3.1 score for this vulnerability is a high 8.2, with a CVSS v4.0 score of 8.8, highlighting the significant risk it poses. The attack vector is network-based (AV:N), requires no privileges (PR:N), and no user interaction (UI:N), making it relatively easy for adversaries to exploit.

MZ Automation, the vendor of the affected software, has released version 2.4.1 of lib60870 to address this vulnerability. Users are strongly advised to update to this latest version or a later release to mitigate the risk. Detailed information about the fix and security advisories can be found on the vendor's GitHub repository.

The advisory emphasizes that this vulnerability impacts critical infrastructure sectors globally, underscoring the potential for widespread disruption. The widespread use of lib60870 in SCADA systems and other industrial applications means that a successful attack could have severe consequences for essential services.

CISA recommends that organizations implement defensive measures to minimize the risk of exploitation. These measures include minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks behind firewalls and isolating them from business networks. Secure remote access methods like VPNs should be used when necessary, and all VPNs should be kept updated.

While no public exploitation of this specific vulnerability has been reported to CISA at this time, the potential impact warrants immediate attention. Organizations should conduct thorough impact analyses and risk assessments before deploying any defensive measures. CISA also encourages reporting of any suspected malicious activity for correlation with other incidents.

This advisory serves as a critical reminder of the ongoing security challenges facing the industrial control systems sector. The complexity and interconnectedness of these systems, coupled with the potential for severe real-world consequences, necessitate a proactive and vigilant approach to cybersecurity.

This advisory details four additional vulnerabilities in MZ Automation libIEC61850, including stack-based and heap-based buffer overflows (CVE-2026-50039, CVE-2026-49035) and NULL pointer dereferences (CVE-2026-50103, CVE-2026-50032). These new findings expand upon the previously reported denial-of-service vulnerability, with some allowing for arbitrary code execution under specific conditions, further increasing the risk to critical infrastructure.

Synthesized by Vypr AI