MZ Automation Libiec61850: Four High-Severity Flaws Disclosed Together
Key findings • Four vulnerabilities in MZ Automation's Libiec61850 disclosed on July 23, 2026. • Vulnerabilities include heap/stack buffer overflows and NULL pointer dereferences. • Explo…

Key findings
- Four vulnerabilities in MZ Automation's Libiec61850 disclosed on July 23, 2026.
- Vulnerabilities include heap/stack buffer overflows and NULL pointer dereferences.
- Exploitation could lead to service crashes or remote code execution.
- Affected versions are Libiec61850 v1.0.0 through v1.6.1.
- Impacts critical infrastructure sectors: manufacturing, energy, transportation.
On July 23, 2026, a batch of four vulnerabilities was disclosed for MZ Automation's Libiec61850 software, impacting critical infrastructure sectors including critical manufacturing, energy, and transportation systems. The vulnerabilities, ranging in severity from medium to high, could allow unauthenticated network-adjacent attackers to crash services or execute arbitrary code, potentially disrupting or compromising essential functions.
The disclosed vulnerabilities include:
- **Heap-based Buffer Overflow (CVE-2026-49035):** This high-severity vulnerability (CVSSv3 8.1) can be triggered by a crafted MMS Initiate request. While remote code execution (RCE) has been demonstrated with ASLR disabled, memory corruption or denial of service may occur in environments where ASLR is enabled.
- **NULL Pointer Dereference in MMS Write Named Variable List (CVE-2026-50032):** Rated as high severity (CVSSv3 7.5), this flaw allows a network-adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.
- **Stack-based Buffer Overflow (CVE-2026-50039):** Also a high-severity vulnerability (CVSSv3 7.5), this flaw may permit an attacker to cause memory corruption via a ReadRequest.
- **NULL Pointer Dereference in L2 GOOSE and R-GOOSE Parser (CVE-2026-50103):** This medium-severity vulnerability (CVSSv3 6.5) could allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame with a malformed TLV value.
According to CISA, successful exploitation of these vulnerabilities could lead to disruption or compromise of critical IEC 61850 services. The affected versions of MZ Automation Libiec61850 are versions 1.0.0 through 1.6.1. Patches or updated versions are expected to address these issues. Users are advised to consult vendor advisories for specific mitigation and remediation steps.
The coordinated disclosure of these vulnerabilities highlights the importance of timely patching and security updates for industrial control systems. Given the widespread deployment of Libiec61850 in critical infrastructure globally, prompt attention to these security advisories is crucial to maintain operational integrity and prevent potential disruptions.