PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66360 MZ Automation GmbH CVE debrief

A vulnerability in the ISO Presentation layer of libiec61850, a library used for IEC 61850 communication, allows an attacker to trigger a denial-of-service condition. The flaw occurs during normal mode negotiation and is caused by a missing length check in the processing of encoded presentation data. A crafted TCP/102 connection attempt can trigger the issue, leading to a process termination.

Vendor
MZ Automation GmbH
Product
libiec61850
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-09-08
Advisory published
2026-07-30
Advisory updated
2026-09-08

Who should care

Defenders of ICS environments using libiec61850 should assess exposure and prioritize verifying and applying patches from MZ Automation GmbH. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review the affected scope, severity, and vendor guidance to ensure the security and reliability of critical infrastructure operations.

Why it matters

CVE-2026-66360 is a vulnerability in the libiec61850 library that can lead to a denial-of-service condition in ICS environments. Defenders should assess exposure, prioritize patching, and monitor for potential attacks.

  • Denial-of-service condition in ICS environments
  • Potential disruption of critical infrastructure operations
  • Need for verification and application of patches from MZ Automation GmbH
  • Possible impact on ICS security and reliability

Technical summary

The ISO Presentation layer in libiec61850 contains a flaw in handling specific parameters during normal mode negotiation. A missing length check allows an attacker-controlled field with a zero-length value to trigger a bounded heap over-read, causing the process to terminate and leading to a denial-of-service condition. This vulnerability affects ICS environments using libiec61850, and defenders should assess exposure and prioritize patching from MZ Automation GmbH. The technical impact is a denial-of-service condition, and the affected product context is libiec61850 library used for IEC 61850 communication.

Defensive priority

Defenders should prioritize verifying and applying patches from the vendor, MZ Automation GmbH, and assess exposure in ICS environments.

Recommended defensive actions

  • Verify and apply patches from MZ Automation GmbH
  • Assess exposure in ICS environments
  • Monitor for crafted TCP/102 connection attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected vendor. ICS-CERT references are also provided. Defenders should verify the affected product deployments, assess exposure, and prioritize patching from MZ Automation GmbH. The evidence is limited, and further verification is needed to confirm the affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-66360 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-66360

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-66360 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66360

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.