Junglewise Threat Intelligence

CVE-2026-49035: MZ Automation libIEC61850 heap overflow in MMS Initiate request

CVE-2026-49035 · Severity: high · CVSS 8.1 · Published 2026-07-23

Executive brief

MZ Automation libIEC61850 is a software library used in industrial control systems for communication in sectors like energy and transportation. A security flaw allows an attacker to send a specially crafted request that can crash the service or potentially take full control of the affected device. This could lead to a loss of visibility and control over critical infrastructure operations.

Technical details

A heap-based buffer overflow (CWE-122) exists in MZ Automation libIEC61850 versions v1.0.0 through v1.6.1. The vulnerability is triggered when the library processes a specially crafted Manufacturing Message Specification (MMS) Initiate request. An unauthenticated remote attacker can exploit this to cause memory corruption. While Address Space Layout Randomization (ASLR) may mitigate the impact to a denial of service (DoS), remote code execution (RCE) has been demonstrated in environments where ASLR is disabled. Users are advised to update to the latest build available on the vendor's GitHub repository.

Affected products

  • MZ Automation libIEC61850 v1.0.0 to v1.6.1

Timeline

  • 2026-07-23: advisory: Initial publication by CISA and NVD
  • 2026-07-23: patched: Vendor fix recommended via latest build update

References

Related threats